Harden SSRF guards: validate all DNS records, unwrap IPv4-mapped IPv6, add reserved/multicast/CGNAT, pin HTTP fetch to close validate->fetch TOCTOU, osint_headers no longer fails open.
Harden SSRF guards: validate all DNS records, unwrap IPv4-mapped IPv6, add reserved/multicast/CGNAT, pin HTTP fetch to close validate->fetch TOCTOU, osint_headers no longer fails open.