They really do need to do that in order for Podcasts to be supported on very old devices (that only support Spotify's APIs and DRM-ed Vorbis files), which I appreciate as a user of such an old device myself.
That said, they allow distributors to opt into "Passthrough" MP3 delivery to all modern devices (including browsers – just check the network tab in developer tools!), although it's not the default.
If they just served podcasts directly from third parties, third parties would be able at least in theory to push potentially malicious data to the Spotify app (and Spotify users' devices).
As for performance, if the third party has an outage, then it would make Spotify look broken. And who knows if the third party site can serve the traffic well enough for a good experience.