Opening a connection to a URL built from a variable can let an attacker reach internal services (SSRF).
Validate the target host against an allowlist and reject internal or link-local addresses.