1. Insert the following line in your ModSecurity configuration file:

SecRule REQUEST_HEADERS "()\s*{" "log,deny"

2. Restart Apache