I wasn't able to replace the http.sys directly, but on a fresh boot (before launching vs2019) I was able to rename http.sys to http_.sys (or some similar backup name) - then I put the "good" http.sys in place and I no longer get blue screen.
I tried this for about a week and no blue screen.
I tested some more by putting the "bad" http.sys back in place and got a blue screen within a couple hours.
I think it has something to do with Microsoft's fix for this vulnerability, but I have not tried to work on this any further after figuring out the http.sys trick. Zero Day Initiative — CVE-2021-31166: A Wormable Code Execution Bug in HTTP.sys
Maybe a rushed patch? Either way, Microsoft, Please fix this.