RUSTSEC-2026-0221: `event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`
- Dominant language
- Rust
- Stars
- 1.4k
- Forks
- 567
- Avg merge
- 2d 2h
- Merged PRs (30d)
- 93
Description
> `event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`
| Details | |
| ------------------- | ---------------------------------------------- |
| Status | unsound |
| Package | `event-listener` |
| Version | `5.4.1` |
| URL | [https://github.com/smol-rs/event-listener/pull/163](https://github.com/smol-rs/event-listener/pull/163) |
| Date | 2026-07-13 |
Affected versions of `event-listener` unconditionally implement `Send` and
`Sync` for `StackSlot<'_, T>`, the stack-allocated listener type created
by the `listener!` macro.
This allows a `!Send` tag type set via `Event::with_tag` to be moved to
another thread and accessed via `StackSlot::wait`, causing a data race in safe
code.
See [advisory page](https://rustsec.org/advisories/RUSTSEC-2026-0221.html) for additional details.
Contributor guide
Research direction
The issue identifies event-listener 5.4.1 and links to upstream PR 163 and the RustSec advisory, but names no files or tests in iceberg-rust. Start by reading those references and inspecting the repository's dependency declarations; done is undefined because the issue does not state an update or mitigation.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100