Currently using loadAs to parse http message, need to add unit test ensure no CVE issue. as with JSON, not to enable any object deserialization.

Comment From: CAICAIIs

Hi,I would like to work on this issue.