Hehe, when I heard about the attack a couple of days ago I was interested to know if Nginx was affected and did a search on Google for the CVE of that attack followed by the name of Nginx. I didn’t find anything relevant so I assumed that Nginx was not affected. Turns out that was not a good assumption :p
I immediately thought I’m happy not having to operate anything with nginx in front of it.
This headline is pretty misleading as the article outlines you would need a fairly non-standard config to be exploited like this.
Versus many other products that the stock configs are vulnerable.