The existing check only blocks known localhost hostnames. This adds DNS
resolution and private IP range blocking to prevent SSRF via:
- Domains resolving to private IPs (192.168.x.x, 10.x.x.x, etc.)
- Access to cloud metadata endpoints (169.254.169.254)
- IPv6 link-local and unique-local addresses