HTTP is saved here because headers aren't allowed to contain control characters. A server that is strict enough to only recognize CRLF will hopefully also be strict enough to reject requests that contain invalid characters.
The situation is different with SMTP, see https://www.postfix.org/smtp-smuggling.html