aws / aws/aws-lambda-web-adapter

RUSTSEC-2026-0221: `event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`

Open
#814 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Rust
Stars
2.7k
Forks
161
Avg merge
2d 10h
Merged PRs (30d)
2

Description

> `event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`

| Details | |
| ------------------- | ---------------------------------------------- |
| Status | unsound |
| Package | `event-listener` |
| Version | `5.4.1` |
| URL | [https://github.com/smol-rs/event-listener/pull/163](https://github.com/smol-rs/event-listener/pull/163) |
| Date | 2026-07-13 |

Affected versions of `event-listener` unconditionally implement `Send` and
`Sync` for `StackSlot<'_, T>`, the stack-allocated listener type created
by the `listener!` macro.

This allows a `!Send` tag type set via `Event::with_tag` to be moved to
another thread and accessed via `StackSlot::wait`, causing a data race in safe
code.

See [advisory page](https://rustsec.org/advisories/RUSTSEC-2026-0221.html) for additional details.

Contributor guide

Open the contributing guide

Research direction

The report names event-listener 5.4.1 and links upstream pull request 163; start by checking whether this repository depends on that version and reviewing the advisory. Done means the affected dependency is no longer present at the vulnerable version.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.