Fetching URLs from user input without validation can allow SSRF attacks.
Validate and allowlist URLs before making server-side HTTP requests.