Do you mean the ability of jellyfin to access the internet or the ability for network access to jellyfin.
If you mean the second then you need to map ports https://docs.docker.com/get-started/docker-concepts/running-containers/publishing-ports/
If you mean the first then something is wonky, but also using host mode still doesn't negate the point. You're still only allowing the processes in the container to access only directories you've specified and isolated them from the other processes on the system. It's about limited the blast radius if an exploit against your network application occurred
The fact that every company involved other than nvidia is hemorrhaging cash and has no path to profitability.