CVE-2018-17143

The html package (aka x/net/html) through 2018-09-17 in Go mishandles