CVE-2018-17847

The html package (aka x/net/html) through 2018-09-25 in Go mishandles