NSS 3.131 release notes

Introduction

Network Security Services (NSS) 3.131 was released on 6 October 2026.

Distribution Information

The HG tag is NSS_3_131_RTM. NSS 3.131 requires NSPR 4.39 or newer.

NSS 3.131 source distributions are available on ftp.mozilla.org for secure HTTPS download:

Other releases are available Release Notes.

Changes in NSS 3.131

  • Bug 2078438 - remove unused private pkcs12, pkcs7, and smime functions.

  • Bug 2070738 - Fix generating nss.pc with system-nspr.

  • Bug 2066048 - replace sslSecurityInfo peerCert with peerCertDER.

  • Bug 2067244 - remove support for inherited DSA parameters in libssl.

  • Bug 2017995 - Fix issues with Unwrapping keys using tokens in FIPS mode.

  • Bug 2069886 - remove Windows-only AES-CTR implementation.

  • Bug 2069887 - improve algorithm policy enforcement for ML-DSA.

  • Bug 2064512 - reject non-RFC 8410 curve OIDs when encoding an X25519 or Ed25519 SubjectPublicKeyInfo.

  • Bug 2076212 - Clear freed CMS members in the destructors.

  • Bug 2076212 - Release the previous signer certificate when re-verifying a PKCS#7 signature.

  • Bug 2076212 - Make SEC_PKCS7DecoderAbort fail the decode.

  • Bug 2076212 - Fail closed after an incomplete PKCS#12 decode.

  • Bug 2076240 - remove unused NSSCryptoContext and NSSTrustDomain functions.

  • Bug 1993638 - can’t import eddsa .p12 from OpenSSL.

  • Bug 2055638 - fix clang format.

  • Bug 2072045 - pk12util fails to import private key into SoftHSM token despite initialized slot and valid PKCS#12 file.

  • Bug 2075580 - p7content: open output file in binary mode.

  • Bug 2068388 - fix msvc build error.

  • Bug 2072416 - use SEC_ASN1_GET for SEC_OctetStringTemplate in der_gtest.

  • Bug 2074663 - remove unused and unexported CERT_ functions.

  • Bug 2072416 - fix leak when decoding nested indefinite length octet strings with null arena.

  • Bug 2072416 - Keep ASN.1 constructed-string substring allocations out of the caller’s SECItem.

  • Bug 2075525 - link softoken_static_gtest against advapi32 on Windows.

  • Bug 2055638 - add regression test for bug 2054616.

  • Bug 2055583 - add regression test for bug 2054719.

  • Bug 2075289 - httpserv: OCSP responses are sent without a Content-Length header.

  • Bug 2075021 - remove unused private PK11_ functions.

  • Bug 2075291 - avoid NULL dereference in NSS_CMSDigestContext_StartMultiple error path.

  • Bug 2073293 - add CERT_GetDERCertTrust.

  • Bug 1719827 - auto update key4db entry KDF iteration count on login.

  • Bug 2068388 - reject RSA public exponents larger than 32 bits.

  • Bug 2075024 - improve mach support for dist builds.

  • Bug 2037628 - protect PK11SlotInfo::lastLoginCheck with PK11SlotInfo::nssTokenLock.

  • Bug 2047771 - fix fips failures in debug builds.

  • Bug 2068381 - fix error path double free of param_free in PK11_UnwrapPrivKey.

  • Bug 2074968 - stub out DER_Lengths.