Source code

Revision control

Copy as Markdown

Other Tools

(mozilla-projects-nss-nss-3-130-release-notes)=
# NSS 3.130 release notes
## Introduction
:::{container}
Network Security Services (NSS) 3.130 was released on *23 September 2026*.
:::
## Distribution Information
:::{container}
The HG tag is NSS_3_130_RTM. NSS 3.130 requires NSPR 4.39 or newer.
NSS 3.130 source distributions are available on ftp.mozilla.org for secure HTTPS download:
- Source tarballs:
Other releases are available {ref}`mozilla-projects-nss-releases`.
:::
(changes-in-nss-3-130)=
## Changes in NSS 3.130
:::{container}
- Bug 2072042 - selfserv: drain connections before closing.
- Bug 2072396 - reduce core file detection frequency in CI runs.
- Bug 2074429 - applied clang-format on nss.
- Bug 2074515 - Include blapit.h to expose AES_BLOCK_SIZE and SHA_*_LENGTH.
- Bug 2073728 - remove some unused types and functions from lib/pki.
- Bug 2012680 - Testcases for DER_GetInteger error handling.
- Bug 2054712 - Don't accept post-handshake CertificateRequest in DTLS.
- Bug 1951159 - release the decoded certificate when CERT_NewTempCertificate fails.
- Bug 2072384 - remove unnecessary certs dependencies in CI graph.
- Bug 2072554 - add missing return in do_key_slot when no internal key slot.
- Bug 2072682 - initialize referenceCount in crlutil's CRL allocations.
- Bug 2072682 - take a reference in cmsutil's CMS decrypt-key callback.
- Bug 2072682 - release-assert softoken session and db reference counts.
- Bug 2072682 - release-assert stan object reference counts.
- Bug 2072682 - release-assert pk11wrap slot, module and symkey reference counts.
- Bug 2072682 - release-assert SSL reference counts.
- Bug 2072682 - release-assert CRL and GeneralNameList reference counts.
- Bug 2072682 - free never-live symkeys directly in pk11_getKeyFromList.
- Bug 2072682 - abort on detected key object double frees.
- Bug 2072633 - return CKR_HOST_MEMORY when PORT_NewArena fails in jpakesftk.c.
- Bug 2072389 - fix uninitialized SECItem.type in SECKEY_ConvertToPublicKey.
- Bug 2047359 - propagate the PKCS#12 max element length to nested decoders.
- Bug 2068001 - Switch NSS to WIN95 target and remove Windows fiber code.
- Bug 2030245 - Add Windows ARM64 build support to NSS.
- Bug 2019001 - Update policy for mlkem1024 named group and others.
- Bug 2061391 - perform session object removals under slot lock.
- Bug 2028690 - Keep the default input size limit in NSS_CMSMessage_CreateFromDER.
- Bug 2028690 - Thread element limits through the QuickDER decoder and raise them for CRLs.
- Bug 2028690 - Limit ASN.1 group element count and total streamed input.
- Bug 2028690 - Add SEC_QuickDERDecodeItemWithLimits.
- Bug 2028690 - Place a default size limit on ASN.1 decoder inputs.
- Bug 1951159 - populate NSSCertificate::id at creation.
- Bug 2064306 - avoid VLA in tls_ech_unittest.cc.
- Bug 2070118 - Change the error from decode_error to illegal_parameter for the case when update field in Key Update is neither update_requested nor update_not_requested.
- Bug 2064311 - Remove HPKE internals from public headers.
- Bug 2064306 - HPKE P-256 and P-384 KEMs.
- Bug 2070669 - NSS release process improvements.
- Bug 2070421 - Set _NSPR_BUILD_ for Windows builds.
- Bug 2064502 - add tsan build for NSS in treeherder.
:::