The problem is exploits, it's a hardly maintained code base that is old.
Just look at the recent WebP zero day, similar issues could very well exist...