GoFiber never set HSTS header in helmet middleware due to incorrect protocol check (CVE-2026-53624) | HOL Guard CVE