Source code

Revision control

Copy as Markdown

Other Tools

(mozilla-projects-nss-nss-3-131-release-notes)=
# NSS 3.131 release notes
## Introduction
:::{container}
Network Security Services (NSS) 3.131 was released on *6 October 2026*.
:::
## Distribution Information
:::{container}
The HG tag is NSS_3_131_RTM. NSS 3.131 requires NSPR 4.39 or newer.
NSS 3.131 source distributions are available on ftp.mozilla.org for secure HTTPS download:
- Source tarballs:
Other releases are available {ref}`mozilla-projects-nss-releases`.
:::
(changes-in-nss-3-131)=
## Changes in NSS 3.131
:::{container}
- Bug 2078438 - remove unused private pkcs12, pkcs7, and smime functions.
- Bug 2070738 - Fix generating nss.pc with system-nspr.
- Bug 2066048 - replace sslSecurityInfo peerCert with peerCertDER.
- Bug 2067244 - remove support for inherited DSA parameters in libssl.
- Bug 2017995 - Fix issues with Unwrapping keys using tokens in FIPS mode.
- Bug 2069886 - remove Windows-only AES-CTR implementation.
- Bug 2069887 - improve algorithm policy enforcement for ML-DSA.
- Bug 2064512 - reject non-RFC 8410 curve OIDs when encoding an X25519 or Ed25519 SubjectPublicKeyInfo.
- Bug 2076212 - Clear freed CMS members in the destructors.
- Bug 2076212 - Release the previous signer certificate when re-verifying a PKCS#7 signature.
- Bug 2076212 - Make SEC_PKCS7DecoderAbort fail the decode.
- Bug 2076212 - Fail closed after an incomplete PKCS#12 decode.
- Bug 2076240 - remove unused NSSCryptoContext and NSSTrustDomain functions.
- Bug 1993638 - can't import eddsa .p12 from OpenSSL.
- Bug 2055638 - fix clang format.
- Bug 2072045 - pk12util fails to import private key into SoftHSM token despite initialized slot and valid PKCS#12 file.
- Bug 2075580 - p7content: open output file in binary mode.
- Bug 2068388 - fix msvc build error.
- Bug 2072416 - use SEC_ASN1_GET for SEC_OctetStringTemplate in der_gtest.
- Bug 2074663 - remove unused and unexported CERT_ functions.
- Bug 2072416 - fix leak when decoding nested indefinite length octet strings with null arena.
- Bug 2072416 - Keep ASN.1 constructed-string substring allocations out of the caller's SECItem.
- Bug 2075525 - link softoken_static_gtest against advapi32 on Windows.
- Bug 2055638 - add regression test for bug 2054616.
- Bug 2055583 - add regression test for bug 2054719.
- Bug 2075289 - httpserv: OCSP responses are sent without a Content-Length header.
- Bug 2075021 - remove unused private PK11_ functions.
- Bug 2075291 - avoid NULL dereference in NSS_CMSDigestContext_StartMultiple error path.
- Bug 2073293 - add CERT_GetDERCertTrust.
- Bug 1719827 - auto update key4db entry KDF iteration count on login.
- Bug 2068388 - reject RSA public exponents larger than 32 bits.
- Bug 2075024 - improve mach support for dist builds.
- Bug 2037628 - protect PK11SlotInfo::lastLoginCheck with PK11SlotInfo::nssTokenLock.
- Bug 2047771 - fix fips failures in debug builds.
- Bug 2068381 - fix error path double free of param_free in PK11_UnwrapPrivKey.
- Bug 2074968 - stub out DER_Lengths.
:::