I have two vhosts : one on domain.tld port 80, the other on sub.domain.tld port 443 with SSL on. I added a CNAME entry on my DNS server that redire
If these are your only server blocks, then they are also your defacto default server blocks for port 443 and port 80 respectively. See this document for details.
If you do not want this, you need to declare a default server block. A minimalist definition might be:
server {
listen 80 default_server;
listen 443 default_server;
deny all;
}