NSS 3.131 release notes
Introduction
Network Security Services (NSS) 3.131 was released on 6 October 2026.
Distribution Information
The HG tag is NSS_3_131_RTM. NSS 3.131 requires NSPR 4.39 or newer.
NSS 3.131 source distributions are available on ftp.mozilla.org for secure HTTPS download:
Other releases are available Release Notes.
Changes in NSS 3.131
Bug 2078438 - remove unused private pkcs12, pkcs7, and smime functions.
Bug 2070738 - Fix generating nss.pc with system-nspr.
Bug 2066048 - replace sslSecurityInfo peerCert with peerCertDER.
Bug 2067244 - remove support for inherited DSA parameters in libssl.
Bug 2017995 - Fix issues with Unwrapping keys using tokens in FIPS mode.
Bug 2069886 - remove Windows-only AES-CTR implementation.
Bug 2069887 - improve algorithm policy enforcement for ML-DSA.
Bug 2064512 - reject non-RFC 8410 curve OIDs when encoding an X25519 or Ed25519 SubjectPublicKeyInfo.
Bug 2076212 - Clear freed CMS members in the destructors.
Bug 2076212 - Release the previous signer certificate when re-verifying a PKCS#7 signature.
Bug 2076212 - Make SEC_PKCS7DecoderAbort fail the decode.
Bug 2076212 - Fail closed after an incomplete PKCS#12 decode.
Bug 2076240 - remove unused NSSCryptoContext and NSSTrustDomain functions.
Bug 1993638 - can’t import eddsa .p12 from OpenSSL.
Bug 2055638 - fix clang format.
Bug 2072045 - pk12util fails to import private key into SoftHSM token despite initialized slot and valid PKCS#12 file.
Bug 2075580 - p7content: open output file in binary mode.
Bug 2068388 - fix msvc build error.
Bug 2072416 - use SEC_ASN1_GET for SEC_OctetStringTemplate in der_gtest.
Bug 2074663 - remove unused and unexported CERT_ functions.
Bug 2072416 - fix leak when decoding nested indefinite length octet strings with null arena.
Bug 2072416 - Keep ASN.1 constructed-string substring allocations out of the caller’s SECItem.
Bug 2075525 - link softoken_static_gtest against advapi32 on Windows.
Bug 2055638 - add regression test for bug 2054616.
Bug 2055583 - add regression test for bug 2054719.
Bug 2075289 - httpserv: OCSP responses are sent without a Content-Length header.
Bug 2075021 - remove unused private PK11_ functions.
Bug 2075291 - avoid NULL dereference in NSS_CMSDigestContext_StartMultiple error path.
Bug 2073293 - add CERT_GetDERCertTrust.
Bug 1719827 - auto update key4db entry KDF iteration count on login.
Bug 2068388 - reject RSA public exponents larger than 32 bits.
Bug 2075024 - improve mach support for dist builds.
Bug 2037628 - protect PK11SlotInfo::lastLoginCheck with PK11SlotInfo::nssTokenLock.
Bug 2047771 - fix fips failures in debug builds.
Bug 2068381 - fix error path double free of param_free in PK11_UnwrapPrivKey.
Bug 2074968 - stub out DER_Lengths.