<!-- For help and support please go here: - https://security.stackexchange.com/questions/tagged/owasp-crs Ask general usage questions and participate in discussions on the CRS: - https://groups.google.com/a/owasp.org/g/modsecurity-core-rule-set-project --> ### Motivation <!-- A clear and concise description of what the motivation for the --> <!-- new feature is, and what problem it is solving. --> Authorization Bypass in Next.js Middleware https://github.com/advisories/GHSA-f82v-jwr5-mffw ### Proposed solution <!-- A clear and concise description of the feature you would like --> <!-- to add, and how it solves the motivating problem. --> Add rule to detect requests containing header `x-middleware-subrequest`