4.4.2
Security fix: bounds the multiparameter position in search params (created_at(1i) and friends) and drops malformed keys, closing a memory-exhaustion denial of service where a crafted request such as q[created_at(100000000000i)]=1 made the server allocate an array of that size. Fixed in 4.4.2, 5.0.1 and 6.0.0. Reported by @connorshea.
GHSA-vxc9-rm8f-p56j: https://github.com/activerecord-hackery/ransack/security/advisories/GHSA-vxc9-rm8f-p56j