(mozilla-projects-nss-nss-3-127-release-notes)= # NSS 3.127 release notes ## Introduction :::{container} Network Security Services (NSS) 3.127 was released on *13 August 2026*. ::: ## Distribution Information :::{container} The HG tag is NSS_3_127_RTM. NSS 3.127 requires NSPR 4.39 or newer. NSS 3.127 source distributions are available on ftp.mozilla.org for secure HTTPS download: - Source tarballs: Other releases are available {ref}`mozilla-projects-nss-releases`. ::: (changes-in-nss-3-127)= ## Changes in NSS 3.127 :::{container} - Bug 2060720 - Round ECH ClientHelloInner padding up to a multiple of 32. - Bug 2063071 - make selfserv listen on IPv6 wildcard on dual-stack hosts. - Bug 2059176 - EC_DerivePublicKey() failure is not propagated in sftk_mkPrivKey(). - Bug 2052210 - Generate additional test message for Thunderbird (HTML with remote image). - Bug 1869493 - Heap-buffer overflow in AES Keywrap. - Bug 2054609 - remove cipher suite order exception from bug 946147. - Bug 2061107 - restore pkcs12.h for source compatibility. - Bug 2056291 - remove support for pre-v1.0 PKCS#12. - Bug 2054719 - fix content type tag for CMS AuthEnvelopedData plaintext. - Bug 2060118 - remove DH_GenParam support. - Bug 2053831 - clang format. - Bug 2054714 - avoid leaking stale ECH outer extensions across HRR. - Bug 2053831 - Drop CKF_VERIFY flag from CKM_HKDF_DATA derivation in ECH GREASE. - Bug 2053831 - Adjust PK11_Derive and TLS 1.3 derivation templates for CKM_HKDF_DATA and CKO_DATA compliance. - Bug 2053831 - Use CKF_HKDF_SALT_DATA in tls13_HkdfExtract for CKO_DATA keys per PKCS#11 v3.2. - Bug 2057184 - Enable -Wunused-but-set-variable/-global in werror.py. - Bug 2056846 - Remove unused policy string callback to fix -Wunused-but-set-global. - Bug 2052709 - Convert NSS 3.126 release notes to Markdown. - Bug 2052709 - Rename doc/rst to doc/src and update references. - Bug 2052709 - Apply markdownlint to the converted Markdown docs. - Bug 2052709 - Fix Markdown documentation build warnings. - Bug 2052709 - Convert documentation from reStructuredText to Markdown (automated). :::