PT-2026-20237 · Rocket · Rocket Trufusion Enterprise

Published

2026-02-17

·

Updated

2026-03-23

·

CVE-2025-32355

CVSS v3.1

7.3

High

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Rocket TRUfusion Enterprise versions through 7.10.4.0
Description The Rocket TRUfusion Enterprise reverse proxy is misconfigured, permitting the specification of absolute URLs within HTTP request lines. This configuration flaw allows the proxy to load resources from the provided URL.
Recommendations Update Rocket TRUfusion Enterprise to a version later than 7.10.4.0.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-32355

Affected Products

Rocket Trufusion Enterprise