- Add _validate_url_host() to check allowlist before urlopen() - Validate both original URL and redirect target - Reject localhost, internal IPs, and non-allowlisted hosts - Add 2 unit tests for disallowed host rejection - Prevents SSRF attacks via malicious source URLs