NSS 3.130 release notes

Introduction

Network Security Services (NSS) 3.130 was released on 23 September 2026.

Distribution Information

The HG tag is NSS_3_130_RTM. NSS 3.130 requires NSPR 4.39 or newer.

NSS 3.130 source distributions are available on ftp.mozilla.org for secure HTTPS download:

Other releases are available Release Notes.

Changes in NSS 3.130

  • Bug 2072042 - selfserv: drain connections before closing.

  • Bug 2072396 - reduce core file detection frequency in CI runs.

  • Bug 2074429 - applied clang-format on nss.

  • Bug 2074515 - Include blapit.h to expose AES_BLOCK_SIZE and SHA_*_LENGTH.

  • Bug 2073728 - remove some unused types and functions from lib/pki.

  • Bug 2012680 - Testcases for DER_GetInteger error handling.

  • Bug 2054712 - Don’t accept post-handshake CertificateRequest in DTLS.

  • Bug 1951159 - release the decoded certificate when CERT_NewTempCertificate fails.

  • Bug 2072384 - remove unnecessary certs dependencies in CI graph.

  • Bug 2072554 - add missing return in do_key_slot when no internal key slot.

  • Bug 2072682 - initialize referenceCount in crlutil’s CRL allocations.

  • Bug 2072682 - take a reference in cmsutil’s CMS decrypt-key callback.

  • Bug 2072682 - release-assert softoken session and db reference counts.

  • Bug 2072682 - release-assert stan object reference counts.

  • Bug 2072682 - release-assert pk11wrap slot, module and symkey reference counts.

  • Bug 2072682 - release-assert SSL reference counts.

  • Bug 2072682 - release-assert CRL and GeneralNameList reference counts.

  • Bug 2072682 - free never-live symkeys directly in pk11_getKeyFromList.

  • Bug 2072682 - abort on detected key object double frees.

  • Bug 2072633 - return CKR_HOST_MEMORY when PORT_NewArena fails in jpakesftk.c.

  • Bug 2072389 - fix uninitialized SECItem.type in SECKEY_ConvertToPublicKey.

  • Bug 2047359 - propagate the PKCS#12 max element length to nested decoders.

  • Bug 2068001 - Switch NSS to WIN95 target and remove Windows fiber code.

  • Bug 2030245 - Add Windows ARM64 build support to NSS.

  • Bug 2019001 - Update policy for mlkem1024 named group and others.

  • Bug 2061391 - perform session object removals under slot lock.

  • Bug 2028690 - Keep the default input size limit in NSS_CMSMessage_CreateFromDER.

  • Bug 2028690 - Thread element limits through the QuickDER decoder and raise them for CRLs.

  • Bug 2028690 - Limit ASN.1 group element count and total streamed input.

  • Bug 2028690 - Add SEC_QuickDERDecodeItemWithLimits.

  • Bug 2028690 - Place a default size limit on ASN.1 decoder inputs.

  • Bug 1951159 - populate NSSCertificate::id at creation.

  • Bug 2064306 - avoid VLA in tls_ech_unittest.cc.

  • Bug 2070118 - Change the error from decode_error to illegal_parameter for the case when update field in Key Update is neither update_requested nor update_not_requested.

  • Bug 2064311 - Remove HPKE internals from public headers.

  • Bug 2064306 - HPKE P-256 and P-384 KEMs.

  • Bug 2070669 - NSS release process improvements.

  • Bug 2070421 - Set NSPR_BUILD for Windows builds.

  • Bug 2064502 - add tsan build for NSS in treeherder.