I've just noticed an issue with the current version of the patch. It should also include 0x20 (space) since that can also be used to manipulate the request.
