ATLAS Landscape
AML.T0034

Cost Harvesting

Adversaries may deliberately drive a victim's AI services beyond normal operating capacity with the intent of increasing the cost of services. This may be achieved via high-volume, low-complexity queries ([Excessive Queries](/techniques/AML.T0034.000)) or low-volume, high-complexity queries ([Resource-Intensive Queries](/techniques/AML.T0034.001)). In Generative AI or Agentic AI systems, adversarial prompts may be introduced into the model's context to cause ([Agentic Resource Consumption](/techniques/AML.T0034.002)). Unlike resource hijacking, where adversaries may leverage AI resources such as computational, memory, or storage for their own purposes, cost harvesting focuses on resource-centric pressure to a service to ultimately cause financial harm to the victim. Cost Harvesting is especially relevant for cloud-hosted, pay-per-use AI/ML platforms (e.g., LLM APIs, generative image services, vision-language pipelines). By manipulating request volume or request complexity, an attacker can: - Inflate the victim's compute or storage consumption, leading to higher operational costs. - Trigger autoscaling mechanisms that provision additional resources, further amplifying cost and exposure. - Saturate internal queues or GPU/TPU pipelines, causing latency spikes, request throttling, or outright service unavailability for legitimate users.

Severity CVE CVSS
CRITICAL CVE-2024-52384 9.9
CRITICAL CVE-2026-30824 9.8
CRITICAL CVE-2025-63389 9.8
CRITICAL CVE-2026-0545 9.1
HIGH GHSA-mcmc-2m55-j8jj 8.8
HIGH CVE-2024-32965 8.6
HIGH CVE-2025-5302 8.6
HIGH CVE-2026-29872 8.2
HIGH CVE-2026-1117 8.2
HIGH CVE-2024-0452 7.7
HIGH CVE-2026-44555 7.6
HIGH CVE-2022-35985 7.5
HIGH CVE-2022-35979 7.5
HIGH CVE-2026-32701 7.5
HIGH CVE-2026-40116 7.5
HIGH CVE-2026-0599 7.5
HIGH CVE-2024-8966 7.5
HIGH CVE-2024-12720 7.5
HIGH CVE-2022-35965 7.5
HIGH CVE-2024-10624 7.5
HIGH CVE-2024-10569 7.5
HIGH CVE-2024-10188 7.5
HIGH CVE-2022-35969 7.5
HIGH CVE-2024-39721 7.5
HIGH CVE-2022-35972 7.5
HIGH CVE-2024-8768 7.5
HIGH CVE-2024-6587 7.5
HIGH CVE-2023-33976 7.5
HIGH CVE-2024-34527 7.5
HIGH CVE-2023-25676 7.5
HIGH CVE-2023-25675 7.5
HIGH CVE-2023-25666 7.5
HIGH CVE-2022-41908 7.5
HIGH CVE-2022-41901 7.5
HIGH CVE-2022-41897 7.5
HIGH CVE-2022-41896 7.5
HIGH CVE-2022-41893 7.5
HIGH CVE-2022-41890 7.5
HIGH CVE-2022-41887 7.5
HIGH CVE-2022-41886 7.5
HIGH CVE-2022-41884 7.5
HIGH CVE-2022-41883 7.5
HIGH CVE-2022-36014 7.5
HIGH CVE-2022-36005 7.5
HIGH CVE-2022-36002 7.5
HIGH CVE-2022-35999 7.5
HIGH CVE-2022-35998 7.5
HIGH CVE-2022-35997 7.5
HIGH CVE-2022-35996 7.5
HIGH CVE-2022-35994 7.5
HIGH CVE-2022-35992 7.5
HIGH CVE-2022-35991 7.5
HIGH CVE-2022-36018 7.5
HIGH CVE-2022-35989 7.5
HIGH CVE-2022-35988 7.5
HIGH CVE-2022-35987 7.5
HIGH CVE-2022-35983 7.5
HIGH CVE-2025-66959 7.5
HIGH CVE-2026-23490 7.5
HIGH CVE-2025-15514 7.5
HIGH CVE-2024-58339 7.5
HIGH CVE-2025-66960 7.5
HIGH CVE-2024-58340 7.5
HIGH CVE-2026-0621 7.5
HIGH CVE-2026-22773 7.5
HIGH CVE-2025-59425 7.5
HIGH CVE-2025-55559 7.5
HIGH CVE-2025-55551 7.5
HIGH CVE-2025-6921 7.5
HIGH CVE-2025-6638 7.5
HIGH CVE-2025-48956 7.5
HIGH CVE-2025-48889 7.5
HIGH CVE-2025-2099 7.5
HIGH CVE-2025-1752 7.5
HIGH CVE-2025-0649 7.5
HIGH CVE-2025-46560 7.5
HIGH CVE-2026-41279 7.5
HIGH GHSA-5ccf-884p-4jjq 7.5
HIGH CVE-2024-8984 7.5
HIGH CVE-2024-8053 7.5
HIGH CVE-2024-7983 7.5
HIGH GHSA-hh3j-9m59-p8vc 7.5
HIGH CVE-2024-12534 7.5
HIGH CVE-2024-12537 7.5
HIGH CVE-2025-0453 7.5
HIGH GHSA-6wj5-5pgr-jwq8 7.5
HIGH CVE-2024-9056 7.5
HIGH CVE-2025-65098 7.4
HIGH CVE-2026-44567 7.3
HIGH CVE-2025-5018 7.1
HIGH CVE-2026-44556 7.1
MEDIUM CVE-2024-28224 6.6
MEDIUM CVE-2022-23585 6.5
MEDIUM GHSA-hf3c-wxg2-49q9 6.5
MEDIUM CVE-2025-14980 6.5
MEDIUM CVE-2025-32381 6.5
MEDIUM CVE-2026-34756 6.5
MEDIUM CVE-2022-23575 6.5
MEDIUM CVE-2024-9277 6.5
MEDIUM CVE-2025-62372 6.5
MEDIUM CVE-2025-13359 6.5
MEDIUM CVE-2025-62426 6.5
MEDIUM CVE-2023-25661 6.5
MEDIUM CVE-2025-29770 6.5
MEDIUM CVE-2024-13698 6.5
MEDIUM CVE-2026-30886 6.5
MEDIUM CVE-2022-23580 6.5
MEDIUM CVE-2026-34755 6.5
MEDIUM CVE-2022-23571 6.5
MEDIUM CVE-2025-1194 6.5
MEDIUM GHSA-mvv8-v4jj-g47j 6.5
MEDIUM CVE-2022-23568 6.5
MEDIUM CVE-2022-23569 6.5
MEDIUM GHSA-vrqm-gvq7-rrwh 6.5
MEDIUM CVE-2022-21738 6.5
MEDIUM CVE-2025-48944 6.5
MEDIUM CVE-2025-48943 6.5
MEDIUM CVE-2022-21732 6.5
MEDIUM CVE-2022-21733 6.5
MEDIUM CVE-2022-23567 6.5
MEDIUM CVE-2025-48887 6.5
MEDIUM CVE-2025-61620 6.5
MEDIUM CVE-2024-11896 6.4
MEDIUM CVE-2024-8939 6.2
MEDIUM CVE-2024-1455 5.9
MEDIUM CVE-2024-12910 5.9
MEDIUM CVE-2026-29772 5.9
MEDIUM CVE-2026-34052 5.9
MEDIUM CVE-2021-29551 5.5
MEDIUM CVE-2025-3730 5.5
MEDIUM CVE-2022-29202 5.5
MEDIUM CVE-2022-29198 5.5
MEDIUM CVE-2022-29196 5.5
MEDIUM CVE-2022-29195 5.5
MEDIUM CVE-2021-41218 5.5
MEDIUM CVE-2021-41200 5.5
MEDIUM CVE-2021-41199 5.5
MEDIUM CVE-2021-41198 5.5
MEDIUM CVE-2021-41197 5.5
MEDIUM CVE-2021-37673 5.5
MEDIUM CVE-2021-37669 5.5
MEDIUM CVE-2021-29543 5.5
MEDIUM CVE-2021-29531 5.5
MEDIUM CVE-2021-29538 5.5
MEDIUM CVE-2021-29526 5.5
MEDIUM CVE-2021-29522 5.5
MEDIUM CVE-2026-40864 5.4
MEDIUM CVE-2025-5197 5.3
MEDIUM CVE-2025-6208 5.3
MEDIUM CVE-2026-2589 5.3
MEDIUM CVE-2024-6845 5.3
MEDIUM CVE-2025-6051 5.3
MEDIUM CVE-2024-6838 5.3
MEDIUM CVE-2025-3263 5.3
MEDIUM CVE-2025-3264 5.3
MEDIUM CVE-2025-3933 5.3
MEDIUM CVE-2026-39411 5.0
MEDIUM CVE-2025-11972 4.9
MEDIUM CVE-2025-31843 4.3
MEDIUM CVE-2025-12732 4.3
MEDIUM CVE-2020-15192 4.3
MEDIUM GHSA-j828-28rj-hfhp 4.3
MEDIUM CVE-2026-6393 4.3
MEDIUM CVE-2025-60511 4.3
MEDIUM CVE-2025-12360 4.3
LOW CVE-2020-26270 3.3
LOW CVE-2025-4287 3.3
LOW CVE-2026-4993 3.3
CRITICAL CVE-2025-34351
UNKNOWN CVE-2024-56516
UNKNOWN CVE-2024-10650
UNKNOWN CVE-2026-4399
UNKNOWN CVE-2025-1975
UNKNOWN CVE-2025-0187
CRITICAL CVE-2025-65015
HIGH CVE-2026-25048
MEDIUM CVE-2026-33123
HIGH CVE-2026-33155
MEDIUM CVE-2025-58446