# Pale Moon 34.2.1_Release — Pale Moon 34.2.1 - Product: Pale Moon (https://whatsnew.fyi/product/pale-moon) - Vendor: Moonchild Productions - Date: 2026-04-28 - Version: 34.2.1_Release - Original notes: https://repo.palemoon.org/MoonchildProductions/Pale-Moon/releases/tag/34.2.1_Release - Permalink: https://whatsnew.fyi/product/pale-moon/releases/34.2.1-release - Labels: Platforms: Windows, Linux What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **fixed** — Fixed a regression leading to cursive languages (where multiple characters combine) not being rendered correctly (e.g. Arabic) - **changed** — Updated cookie magic prefix handling, adding __Http- and __Host-Http- magic prefixes and aligning implementation with RFC 6265bis - **changed** — Updated Brotli library to 1.2.0+ with additional fixes - **changed** — Updated NSS to 3.90.10.0 (UXP) with additional mitigations - **security** — Addressed 50 potential vulnerabilities found applicable and fixed through security audit - **security** — Applied DiD code changes to address 20 security issues This is a bugfix and security release. Note for FreeBSD users: our binaries from this version forward require FreeBSD v14 or later. **Changes/fixes:** - Fixed a regression leading to cursive languages (where multiple characters combine) not being rendered correctly (e.g. Arabic). - Updated our cookie magic prefix handling, adding __Http- and __Host-Http- magic prefixes and aligning our implementation with RFC 6265bis. - Updated our Brotli library to 1.2.0+ (1.2.0 with additional fixes). - Updated NSS to 3.90.10.0 (UXP). For clarity, the version now carries the (UXP) label to distinguish this fork (which has additional mitigations) from the 3.90 branch of NSS maintained by Mozilla. - A large audit of security issues was performed. Many security issues were addressed, including potential crash scenarios and code correctness issues. As a summary: 50 potential vulnerabilities were found applicable and fixed, 20 issues had DiD code changes applied, and 4 were already mitigated by us before being reported. Of the reported vulnerabilities, 270 were not applicable to our code (with the vast majority pertaining to e10s/multi-process browser architecture) and 6 low-impact ones were marked for further investigation at a later time.