Opening a connection to a URL built from a variable host allows server-side request forgery.
Validate the target against an allowlist of permitted hosts and protocols before connecting.