Microsoft.VisualStudio.Threading is vulnerable to Race Condition
15
Low Risk
Affected versions of the Microsoft.VisualStudio.Threading library are vulnerable to a race condition due to the lack of guaranteed ordering when reading this.joinableTask in the lock-free section of the logic. Under certain race conditions, AsyncLazy may wait on the inner task instead of the joinable task when two threads access this code simultaneously, potentially causing the program to hang and leading to a denial of service (DoS).
You are affected if you are using a version that falls within the vulnerable range.
Microsoft.VisualStudio.Threading is vulnerable to Race Condition in versions 17.5.10-alpha - 17.13.60.
Upgrade the Microsoft.VisualStudio.Threading library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant