(mozilla-projects-nss-nss-3-130-release-notes)= # NSS 3.130 release notes ## Introduction :::{container} Network Security Services (NSS) 3.130 was released on *23 September 2026*. ::: ## Distribution Information :::{container} The HG tag is NSS_3_130_RTM. NSS 3.130 requires NSPR 4.39 or newer. NSS 3.130 source distributions are available on ftp.mozilla.org for secure HTTPS download: - Source tarballs: Other releases are available {ref}`mozilla-projects-nss-releases`. ::: (changes-in-nss-3-130)= ## Changes in NSS 3.130 :::{container} - Bug 2072042 - selfserv: drain connections before closing. - Bug 2072396 - reduce core file detection frequency in CI runs. - Bug 2074429 - applied clang-format on nss. - Bug 2074515 - Include blapit.h to expose AES_BLOCK_SIZE and SHA_*_LENGTH. - Bug 2073728 - remove some unused types and functions from lib/pki. - Bug 2012680 - Testcases for DER_GetInteger error handling. - Bug 2054712 - Don't accept post-handshake CertificateRequest in DTLS. - Bug 1951159 - release the decoded certificate when CERT_NewTempCertificate fails. - Bug 2072384 - remove unnecessary certs dependencies in CI graph. - Bug 2072554 - add missing return in do_key_slot when no internal key slot. - Bug 2072682 - initialize referenceCount in crlutil's CRL allocations. - Bug 2072682 - take a reference in cmsutil's CMS decrypt-key callback. - Bug 2072682 - release-assert softoken session and db reference counts. - Bug 2072682 - release-assert stan object reference counts. - Bug 2072682 - release-assert pk11wrap slot, module and symkey reference counts. - Bug 2072682 - release-assert SSL reference counts. - Bug 2072682 - release-assert CRL and GeneralNameList reference counts. - Bug 2072682 - free never-live symkeys directly in pk11_getKeyFromList. - Bug 2072682 - abort on detected key object double frees. - Bug 2072633 - return CKR_HOST_MEMORY when PORT_NewArena fails in jpakesftk.c. - Bug 2072389 - fix uninitialized SECItem.type in SECKEY_ConvertToPublicKey. - Bug 2047359 - propagate the PKCS#12 max element length to nested decoders. - Bug 2068001 - Switch NSS to WIN95 target and remove Windows fiber code. - Bug 2030245 - Add Windows ARM64 build support to NSS. - Bug 2019001 - Update policy for mlkem1024 named group and others. - Bug 2061391 - perform session object removals under slot lock. - Bug 2028690 - Keep the default input size limit in NSS_CMSMessage_CreateFromDER. - Bug 2028690 - Thread element limits through the QuickDER decoder and raise them for CRLs. - Bug 2028690 - Limit ASN.1 group element count and total streamed input. - Bug 2028690 - Add SEC_QuickDERDecodeItemWithLimits. - Bug 2028690 - Place a default size limit on ASN.1 decoder inputs. - Bug 1951159 - populate NSSCertificate::id at creation. - Bug 2064306 - avoid VLA in tls_ech_unittest.cc. - Bug 2070118 - Change the error from decode_error to illegal_parameter for the case when update field in Key Update is neither update_requested nor update_not_requested. - Bug 2064311 - Remove HPKE internals from public headers. - Bug 2064306 - HPKE P-256 and P-384 KEMs. - Bug 2070669 - NSS release process improvements. - Bug 2070421 - Set _NSPR_BUILD_ for Windows builds. - Bug 2064502 - add tsan build for NSS in treeherder. :::