An HTTP request target is built from a variable, allowing server-side request forgery to internal endpoints.
Validate the URL host against an allowlist and reject internal or link-local addresses before making the request.