It's only "dangerous" because the cache server does not care about headers. I don't see how this could affect security without broken cache server in place. If you are using the framework you should know how the dispatching works. I agree it could be disabled by default tough.
It's just an information for the routing system to dispatch a different method on a controller. You could implement a way to use a query string to pass this override too. An API framework does not have to be RESTful. It could work with POST requests only and simulate deletes with something like ?method=delete.
Edit: I saw a GitHub comment that actually says it is possible to use query string to override the method in Play 1.
https://github.com/playframework/play1/issues/1300#issuecomm...
> We've found that although the header is disabled, its still possible to use X-HTTP-Method-Override by passing as a query string