The POC seems to require some semi-esoteric stuff. In the absence of a more general exploit technique, it might be better to more explicitly say "these are configurations you should not use" than being as sweeping as this is (as for some configurations it does look super-frightening). From reading this, my impression is that there are two things people need to do:
1. Switch off untrusted DNS (e.g. Google's) regardless of any POC. Nginx views using these as insecure (fair enough), so they may decline to issue security advisories for any exploit that doing so allows (less fair).
2. In certain circumstances (1) is insufficient; the post details at least some of these. But you need to do (1) regardless.