Does FastCGI have a history of security bugs due to environment var / header confusion or just regular CGI?
Some fcgi libraries may convert the headers into Env Vars to make it "easier" for code, but it is not strictly necessary.
For example, the HTTP header Proxy may be converted to "HTTP_PROXY" and some application servers may interpret it as the environment variable HTTP_PROXY (I seem to remember HHVM did it). Good servers have measures in place to handle that header, but it can bite you if you are implementing a new server.