- Action Pack hardened against open‑redirects, MIME‑parsing backtracking, HTTP token regex DoS, and unsafe polymorphic URL arguments (CVE‑2021‑22903, ‑22902, ‑22904, ‑22885).
- All other Rails components (Active Support, Active Model, Active Record, Action View, etc.) have no changes in this release.