I remember someone posting an article of common nginx config security mistakes but can't find it. Does anyone remember? I would like to read through that again as well.
Not a comprehensive article, but the worst security footgun, by far (IMO), is $uri. It’s completely unsafe to use $uri in basically any directives! You cannot redirect using it, proxy_pass using it, or you will have a bad time.