Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling. CREATE(Triage):(User=admin) CVE-2019-16276