I'm not sure about the "chock full of potential security issues". You have to be careful with trusting environment variables as the Bash guys learned, but I don't know what else there is that is specific to CGI.
Slashdot used apache mod_perl back then. It never forked a process per request.
Edit: Seems I was wrong about the date, it was actually 28-Jul-1997[1], nevertheless slashdot was only launched two months later, and as the link above witnesses didn't seem to have used it at first.
[1]: https://web.archive.org/web/19971210053529/http://perl.apach...
https://en.wikipedia.org/wiki/FastCGI
Also: DOS attacks against capacity sound positively benign compared to what they translate to on cloud : DOS on your credit card.