
Summary: Once a bearer token is set with CURLOPT_XOAUTH2_BEARER, each HTTP request done with the same handler leaks the token itself. Steps To Reproduce: Given the following code: ```c include int main(void) { curl_global_init(CURL_GLOBAL_ALL); CURL* curl = curl_easy_init(); curl_easy_setopt(curl, CURLOPT_HTTPAUTH, CURLAUTH_BEARER); curl_easy_setopt(curl, CURLOPT_XOAUTH2_BEARER, "c4e448d652a961fda0ab64f882c8c161d5985f805d45d80c9ddca108f8e2fde3"); curl_easy_setopt(curl, CURLOPT_HTTPGET, 1L); curl_easy_setopt(curl, CURLOPT_URL, "https://andrea.pappacoda.it"); for (int i = 0; i < 5; i++) { curl_easy_perform(curl); } curl_easy_cleanup(curl); curl_global_cleanup(); } ``` AddressSanitizer reports a memory leak: ```text $ cc -g -fsanitize=address main.c $(pkg-config --cflags --libs libcurl) -o asan && ./asan ================================================================= ==41730==ERROR: LeakSanitizer: detected memory leaks Direct leak of 260 byte(s) in 4 object(s) allocated from: #0 0x7f52f54d97a7 in __interceptor_strdup ../../../../src/libsanitizer/asan/asan_interceptors.cpp:454 #1 0x7f52f54423cd (/lib/x86_64-linux-gnu/libcurl.so.4+0x673cd) SUMMARY: AddressSanitizer: 260 byte(s) leaked in 4 allocation(s). ``` and valgrind does too: text $ cc -g main.c $(pkg-config --cflags --libs libcurl) -o valgrind && valgrind --leak-check=full ./valgrind ==41878== ==41878== HEAP SUMMARY: ==41878== in use at exit: 3,710 bytes in 12 blocks ==41878== total heap...