There are a few reasons your company might be safe:
1. All your sites serve https directly from web servers (no https termination and passthrough as internal http traffic)
2. You use Cloudflare and you cannot reach your sites directly (article says that Cloudflare rewrites all headers so probably avoids problem)
3. Your front end is properly hardened and it prevents malformed or duplicate headers
4. Your front end does not reuse connections to your web server (maybe the quickest emergency bandage?)
5. Your front/back end do not allow chunking (or pipelining).
This is going to affect so many major sites, and requires patches to critical infrastructure: pass me the popcorn so I can watch this horror show unfold.