Passing a variable URL into an HTTP request lets an attacker force requests to internal services.
Validate the URL against an allowlist of trusted hosts before making the request.