NGINX should have really applied for a CVE instead of pretending that they are immune.
Saying Nginx is vulnerable is like saying that the Linux kernel is vulnerable to heartbleed.
Whoever the f*ck had the briliant idea to alter the environment variables of a server child process through incoming HTTP headers should have his browsers environment variables altered by the servers responses.