Response.Redirect targets a URL taken directly from HTTP request input, enabling open redirect.
Validate redirect targets against an allowlist of trusted local paths or hosts.