(mozilla-projects-nss-nss-3-131-release-notes)= # NSS 3.131 release notes ## Introduction :::{container} Network Security Services (NSS) 3.131 was released on *6 October 2026*. ::: ## Distribution Information :::{container} The HG tag is NSS_3_131_RTM. NSS 3.131 requires NSPR 4.39 or newer. NSS 3.131 source distributions are available on ftp.mozilla.org for secure HTTPS download: - Source tarballs: Other releases are available {ref}`mozilla-projects-nss-releases`. ::: (changes-in-nss-3-131)= ## Changes in NSS 3.131 :::{container} - Bug 2078438 - remove unused private pkcs12, pkcs7, and smime functions. - Bug 2070738 - Fix generating nss.pc with system-nspr. - Bug 2066048 - replace sslSecurityInfo peerCert with peerCertDER. - Bug 2067244 - remove support for inherited DSA parameters in libssl. - Bug 2017995 - Fix issues with Unwrapping keys using tokens in FIPS mode. - Bug 2069886 - remove Windows-only AES-CTR implementation. - Bug 2069887 - improve algorithm policy enforcement for ML-DSA. - Bug 2064512 - reject non-RFC 8410 curve OIDs when encoding an X25519 or Ed25519 SubjectPublicKeyInfo. - Bug 2076212 - Clear freed CMS members in the destructors. - Bug 2076212 - Release the previous signer certificate when re-verifying a PKCS#7 signature. - Bug 2076212 - Make SEC_PKCS7DecoderAbort fail the decode. - Bug 2076212 - Fail closed after an incomplete PKCS#12 decode. - Bug 2076240 - remove unused NSSCryptoContext and NSSTrustDomain functions. - Bug 1993638 - can't import eddsa .p12 from OpenSSL. - Bug 2055638 - fix clang format. - Bug 2072045 - pk12util fails to import private key into SoftHSM token despite initialized slot and valid PKCS#12 file. - Bug 2075580 - p7content: open output file in binary mode. - Bug 2068388 - fix msvc build error. - Bug 2072416 - use SEC_ASN1_GET for SEC_OctetStringTemplate in der_gtest. - Bug 2074663 - remove unused and unexported CERT_ functions. - Bug 2072416 - fix leak when decoding nested indefinite length octet strings with null arena. - Bug 2072416 - Keep ASN.1 constructed-string substring allocations out of the caller's SECItem. - Bug 2075525 - link softoken_static_gtest against advapi32 on Windows. - Bug 2055638 - add regression test for bug 2054616. - Bug 2055583 - add regression test for bug 2054719. - Bug 2075289 - httpserv: OCSP responses are sent without a Content-Length header. - Bug 2075021 - remove unused private PK11_ functions. - Bug 2075291 - avoid NULL dereference in NSS_CMSDigestContext_StartMultiple error path. - Bug 2073293 - add CERT_GetDERCertTrust. - Bug 1719827 - auto update key4db entry KDF iteration count on login. - Bug 2068388 - reject RSA public exponents larger than 32 bits. - Bug 2075024 - improve mach support for dist builds. - Bug 2037628 - protect PK11SlotInfo::lastLoginCheck with PK11SlotInfo::nssTokenLock. - Bug 2047771 - fix fips failures in debug builds. - Bug 2068381 - fix error path double free of param_free in PK11_UnwrapPrivKey. - Bug 2074968 - stub out DER_Lengths. :::