Like the Django patch that was released yesterday? (https://www.djangoproject.com/weblog/2013/feb/19/security/)
The fact that the Rails team quickly responds to vulnerabilities should be reassuring not a disincentive to use the framework. All software is subject to vulnerabilities - the recent issues with YAML are a class of exploit common across many frameworks in different ecosystems (Django's TastyPie had a similar issue in the past).