apache / apache/iceberg-rust

RUSTSEC-2026-0221: `event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`

Open
#2,939 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Rust
Stars
1.4k
Forks
567
Avg merge
2d 2h
Merged PRs (30d)
93

Description

> `event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`

| Details | |
| ------------------- | ---------------------------------------------- |
| Status | unsound |
| Package | `event-listener` |
| Version | `5.4.1` |
| URL | [https://github.com/smol-rs/event-listener/pull/163](https://github.com/smol-rs/event-listener/pull/163) |
| Date | 2026-07-13 |

Affected versions of `event-listener` unconditionally implement `Send` and
`Sync` for `StackSlot<'_, T>`, the stack-allocated listener type created
by the `listener!` macro.

This allows a `!Send` tag type set via `Event::with_tag` to be moved to
another thread and accessed via `StackSlot::wait`, causing a data race in safe
code.

See [advisory page](https://rustsec.org/advisories/RUSTSEC-2026-0221.html) for additional details.

Contributor guide

Open the contributing guide

Research direction

The issue identifies event-listener 5.4.1 and links to upstream PR 163 and the RustSec advisory, but names no files or tests in iceberg-rust. Start by reading those references and inspecting the repository's dependency declarations; done is undefined because the issue does not state an update or mitigation.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.