I don't believe in Jellyfin being secure enough to put on the public Internet. In my case, Jellyfin is on my home network, and the box has access to a lot of files and devices.
Fair enough. IME, Jellyfin and (just as importantly -- at least for me) the distribution (Fedora) I use have been very good at patching/releasing updates to both the clients and servers when vulnerabilities are found.
Initially, I stuffed jellyfin (and a bunch of other stuff) behind HAProxy[0], which was fine. Now I don't even bother.
It's been at least three years since I put up my jellyfin server and haven't had any issues at all.
All that said, I understand your trepidation and am glad you found something that works for you!