Applications fetching remote resources from user-supplied URLs without validation, letting attackers reach internal systems.