Fiber: HSTS header never set in helmet middleware due to incorrect protocol check (CVE-2026-53624) | HOL Guard CVE