VDB
KO

RUSTSEC-2026-0221

`event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`

Details

Affected versions of `event-listener` unconditionally implement `Send` and `Sync` for `StackSlot<'_, T>`, the stack-allocated listener type created by the `listener!` macro.

This allows a `!Send` tag type set via `Event::with_tag` to be moved to another thread and accessed via `StackSlot::wait`, causing a data race in safe code.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io / event-listener
Introduced in: 5.1.0 Fixed in: 5.4.2

Upgrade event-listener to 5.4.2 or newer (ecosystem crates.io).

References