

I think you’ve fundamentally misunderstood some of their communication.
There’s the issue I described earlier where it is possible to stream files unauthenticated if you know the folder structure on the video. The devs have responded that they won’t fix this. Outside of streaming content, there’s no other access through this mean. https://github.com/jellyfin/jellyfin/issues/1501
Then there’s the release of 10.11.7 that fixed a number of security issues. https://github.com/jellyfin/jellyfin/releases/tag/v10.11.7 with no major security issues since then. And all the issues were privilagr escalation for a normal user account on jellyfin. So the attacker would already needed to have an account on your server, and only the data that jellyfin could see was at risk, nothing escaped contagion so to say.
They also officially support a reverse proxy set up: https://jellyfin.org/docs/general/post-install/networking/reverse-proxy/.
I have no idea where you’ve got the idea where they themselves claim it’s unsecure to open it to the internet. Of course there’s always a risk associated with exposing something, but jellyfin doesn’t pose any larger risk than anything else you might publish.

I do agree it’s an odd choice not to fix it, and I do wish they would. But for now it’s a risk I’m fine with taking. If my server gets DOSd in the future from multiple unauthenticated streams I sure will be a grumpy git and complain to them, but in the mean time uuh… sharing is caring? 😅