aws / aws/aws-lambda-web-adapter
RUSTSEC-2026-0221: `event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`
- Dominant language
- Rust
- Stars
- 2.7k
- Forks
- 161
- Avg merge
- 2d 10h
- Merged PRs (30d)
- 2
Description
> `event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`
| Details | |
| ------------------- | ---------------------------------------------- |
| Status | unsound |
| Package | `event-listener` |
| Version | `5.4.1` |
| URL | [https://github.com/smol-rs/event-listener/pull/163](https://github.com/smol-rs/event-listener/pull/163) |
| Date | 2026-07-13 |
Affected versions of `event-listener` unconditionally implement `Send` and
`Sync` for `StackSlot<'_, T>`, the stack-allocated listener type created
by the `listener!` macro.
This allows a `!Send` tag type set via `Event::with_tag` to be moved to
another thread and accessed via `StackSlot::wait`, causing a data race in safe
code.
See [advisory page](https://rustsec.org/advisories/RUSTSEC-2026-0221.html) for additional details.
Contributor guide
Research direction
The report names event-listener 5.4.1 and links upstream pull request 163; start by checking whether this repository depends on that version and reviewing the advisory. Done means the affected dependency is no longer present at the vulnerable version.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100