Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey(). There is a clear correlation between execution time and private key length, which may cause disclosure of the length information of the private key. This might allow attackers to conduct timing attacks.
We are going to close this a "not a bug". We believe it is expected behavior. We don't believe the CVE is valid.
@CindyZhouYH, if you can provide a test program and test data we would be happy to revisit it."