tauri-apps / tauri-apps/plugins-workspace

RUSTSEC-2026-0221: `event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`

Open
#3,523 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Rust
Stars
1.8k
Forks
602
Avg merge
4d 14h
Merged PRs (30d)
9

Description

> `event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`

| Details | |
| ------------------- | ---------------------------------------------- |
| Status | unsound |
| Package | `event-listener` |
| Version | `5.4.0` |
| URL | [https://github.com/smol-rs/event-listener/pull/163](https://github.com/smol-rs/event-listener/pull/163) |
| Date | 2026-07-13 |

Affected versions of `event-listener` unconditionally implement `Send` and
`Sync` for `StackSlot<'_, T>`, the stack-allocated listener type created
by the `listener!` macro.

This allows a `!Send` tag type set via `Event::with_tag` to be moved to
another thread and accessed via `StackSlot::wait`, causing a data race in safe
code.

See [advisory page](https://rustsec.org/advisories/RUSTSEC-2026-0221.html) for additional details.

Contributor guide

Open the contributing guide

Research direction

Start with the linked advisory page and upstream event-listener pull request. Search this workspace for its event-listener dependency and check whether the affected 5.4.0 version is used; done means the workspace no longer relies on the vulnerable version and its dependency checks pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.