- Active Support: fixed regex backtracking in Inflector.underscore (CVE‑2023‑22796).
- Active Record: hardened sanitize_sql_comment and added integer width check for PostgreSQL quoting (CVE‑2023‑22794, CVE‑2022‑44566).
- Action Pack: tightened URL host validation to block malicious redirects (CVE‑2023‑22797, CVE‑2023‑22795, CVE‑2023‑22792).