isInList in the safeurl-python package before 1.2 for Python has an insufficiently restrictive regular expression for external domains, leading to SSRF.
"https://github.com/pypa/advisory-database/blob/main/vulns/safeurl-python/PYSEC-2023-298.yaml"