The flaw here is only exploitable by (1) a malicious server, which could anyway just send a malicious binary, no need for header shenanigans, or (2) a MITM. Case 1 is moot, case 2 would be prevented by properly implemented HTTPS.
On the other hand, I don't think it's practical to actually implement HTTPS properly in UEFI, since you'd have to constantly update the trust store, and you'd have to have actual internet access to be be able to check the certificate revocation lists (otherwise, you are vulnerable to surreptitious malicious activity from otherwise trusted CAs).