This vulnerability affects parsing maliciously crafted certificates, so it will mostly affect clients. If your app is fetching data from a 3rd party and validating its certificate, it may be vulnerable, regardless of how you are fronting requests to your site.