I think that good security enhancement would be some max lengths configurations: - maximum length of URL in request line - maximum length of header's name and header's value These are possible attack surfaces.