—
RUSTSEC-2026-0221
`event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`
Details
Affected versions of `event-listener` unconditionally implement `Send` and `Sync` for `StackSlot<'_, T>`, the stack-allocated listener type created by the `listener!` macro.
This allows a `!Send` tag type set via `Event::with_tag` to be moved to another thread and accessed via `StackSlot::wait`, causing a data race in safe code.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io / event-listener
Introduced in:
5.1.0 Fixed in: 5.4.2 Upgrade event-listener to 5.4.2 or newer (ecosystem crates.io).