Servers usually accept data in a thousand ways in a thousand endpoints. Anyone who tries to prevent buffer overflow or slowloris attacks by limiting password length specifically is doing it wrong. An absurdly long password is surely one of the least likely places where a resource-use vulnerability would pop up since the data usually gets sent straight into a 20 year old hash implementation.