NSS 3.130 release notes
Introduction
Network Security Services (NSS) 3.130 was released on 23 September 2026.
Distribution Information
The HG tag is NSS_3_130_RTM. NSS 3.130 requires NSPR 4.39 or newer.
NSS 3.130 source distributions are available on ftp.mozilla.org for secure HTTPS download:
Other releases are available Release Notes.
Changes in NSS 3.130
Bug 2072042 - selfserv: drain connections before closing.
Bug 2072396 - reduce core file detection frequency in CI runs.
Bug 2074429 - applied clang-format on nss.
Bug 2074515 - Include blapit.h to expose AES_BLOCK_SIZE and SHA_*_LENGTH.
Bug 2073728 - remove some unused types and functions from lib/pki.
Bug 2012680 - Testcases for DER_GetInteger error handling.
Bug 2054712 - Don’t accept post-handshake CertificateRequest in DTLS.
Bug 1951159 - release the decoded certificate when CERT_NewTempCertificate fails.
Bug 2072384 - remove unnecessary certs dependencies in CI graph.
Bug 2072554 - add missing return in do_key_slot when no internal key slot.
Bug 2072682 - initialize referenceCount in crlutil’s CRL allocations.
Bug 2072682 - take a reference in cmsutil’s CMS decrypt-key callback.
Bug 2072682 - release-assert softoken session and db reference counts.
Bug 2072682 - release-assert stan object reference counts.
Bug 2072682 - release-assert pk11wrap slot, module and symkey reference counts.
Bug 2072682 - release-assert SSL reference counts.
Bug 2072682 - release-assert CRL and GeneralNameList reference counts.
Bug 2072682 - free never-live symkeys directly in pk11_getKeyFromList.
Bug 2072682 - abort on detected key object double frees.
Bug 2072633 - return CKR_HOST_MEMORY when PORT_NewArena fails in jpakesftk.c.
Bug 2072389 - fix uninitialized SECItem.type in SECKEY_ConvertToPublicKey.
Bug 2047359 - propagate the PKCS#12 max element length to nested decoders.
Bug 2068001 - Switch NSS to WIN95 target and remove Windows fiber code.
Bug 2030245 - Add Windows ARM64 build support to NSS.
Bug 2019001 - Update policy for mlkem1024 named group and others.
Bug 2061391 - perform session object removals under slot lock.
Bug 2028690 - Keep the default input size limit in NSS_CMSMessage_CreateFromDER.
Bug 2028690 - Thread element limits through the QuickDER decoder and raise them for CRLs.
Bug 2028690 - Limit ASN.1 group element count and total streamed input.
Bug 2028690 - Add SEC_QuickDERDecodeItemWithLimits.
Bug 2028690 - Place a default size limit on ASN.1 decoder inputs.
Bug 1951159 - populate NSSCertificate::id at creation.
Bug 2064306 - avoid VLA in tls_ech_unittest.cc.
Bug 2070118 - Change the error from decode_error to illegal_parameter for the case when update field in Key Update is neither update_requested nor update_not_requested.
Bug 2064311 - Remove HPKE internals from public headers.
Bug 2064306 - HPKE P-256 and P-384 KEMs.
Bug 2070669 - NSS release process improvements.
Bug 2070421 - Set NSPR_BUILD for Windows builds.
Bug 2064502 - add tsan build for NSS in treeherder.