Anything on the public internet is some amount of risk.
It sounds reasonably configured, and for a single service that's been fairly robust, the only thing you really should make sure you're doing is updates - better if you configure automatic updates, so you don't even have to think about it.
unattended-upgrades is what you'd want on a Debian-alike for updates, and Overseerr depends on how you installed it.