

The main issue there isn’t the fact that these issues exist. The problem is the Jellyfin devs attitude towards them, most of these problems have been known for years (more than five in some cases) but are largely ignored. Client compatibility is valued over everything else.
There have been plenty of suggestions, ideas and even PRs, but the devs priorities don’t allow for any security centered patches to get merged






There are ways to fix these issues while preserving legacy client support. And honestly I don’t see how changing their database mess would help in solving security issues. In the end they’ll have to change their API to a more secure one, which will definitely disrupt client support for future updates