The valid characters are defined in RFC 7230 and RF
Tomcat在7.0.73,8.0.39,8.5.7版本后,添加了对于http头的验证。具体来说,就是添加了些规则去限制HTTP头的规范性具体来说:org.apache.tomcat.util.http.parser.HttpParser#IS_NOT_REQUEST_TARGET[]中定义了一堆notrequesttargetif(IS_CONTROL[i]||i>127||i==32||i==