Upgrade Path

Nextcloud Server 24.0.0 → 35.0.1

82 versions, 40 critical-change sections in 8 versions (2 repeat an earlier entry), 11 required stops

Required stops

Version by version, oldest first

24.0.1 – 24.0.6: no action items (6 versions)

24.0.7 – 24.0.11: released after 25.0.0; not on this route

24.0.12 2023-04-20

Full release notes for 24.0.12

25.0.0 – 25.0.4: no action items (5 versions)

25.0.5 – 25.0.12: released after 26.0.0; not on this route

25.0.13 2023-10-28

Full release notes for 25.0.13

26.0.0 2023-03-21

Quoted from docs.nextcloud.com/server/latest/admin_manual/release_notes/upgrade_to_26.html

Critical change

System requirements

  • PHP 8.2 is now supported, but 8.1 is recommended.
  • PHP 7.4 is no longer supported.

Critical change

System email

The software component to send system emails (notifications, invites, password reset, etc) had to be replaced. The new library should work without any changes out of the box for most setups.

A brief overview of changes:

  • STARTTLS cannot be enforced. It will be used automatically if the mail server supports it. The encryption type should be set to 'None/STARTTLS' in this case.
  • Self signed certificates now need to be explicitly enabled, see this guide for an example on how to configure this.
  • NTLM authentication for Microsoft Exchange is not supported by the new mailer library. Try using basic authentication instead.

See for more information: Mail Providers.

Critical change

DAV sync tokens retention

A mechanism to clean up old CalDAV and CardDAV sync tokens has been added. See CalDAV retention and CardDAV retention and make sure it fits your installation size.

Critical change

Web server configuration

Full release notes for 26.0.0

26.0.1 – 26.0.2: no action items (2 versions)

26.0.3 – 26.0.12: released after 27.0.0; not on this route

26.0.13 2024-03-28

Full release notes for 26.0.13

27.0.0 2023-06-13

Quoted from docs.nextcloud.com/server/latest/admin_manual/release_notes/upgrade_to_27.html

Critical change

System requirements

  • PHP 8.2 is recommended over PHP 8.1.
  • PHP 8.0 is deprecated and might be removed in Nextcloud 28.

Critical change

Exposed system address book

Nextcloud 27 exposes the system address book. Restrict the enumeration settings if your users should not see other users.

Critical change

Web server configuration

  • The recommended nginx configuration changed as Nextcloud now supports module javascript with the .mjs and audio files with .ogg / .flac extension, make sure to add these extensions to the list of static files.

Full release notes for 27.0.0

27.0.1 – 27.1.4: no action items (7 versions)

27.1.5 – 27.1.9: released after 28.0.0; not on this route

27.1.11 2024-06-25

Full release notes for 27.1.11

28.0.0 2023-12-12

Quoted from docs.nextcloud.com/server/latest/admin_manual/release_notes/upgrade_to_28.html

Critical change

System requirements

  • PHP 8.3 is now supported, but 8.2 is recommended.

Critical change

Web server configuration

  • The recommended nginx configuration changed as Nextcloud Talk now serves audio files with .ogg / .flac extension, make sure to add these extensions to the list of static files.
  • As some core app now make use of JavaScript modules, make sure your web server is not rewriting requests to .mjs files, but serves them with text/javascript MIME type and proper Cache-Control header, like .js and other static file extensions.
  • When using Apache with .htaccess configuration, this will be done automatically.
  • For Nginx, please refer to our recommended Nginx configuration.
  • For other setups, make sure to add .mjs to the list of static file extensions in web server configs and in case define its MIME type in /etc/mime.types.

Critical change

Setup Checks

The setup checks (the ones visible under Administration settings->Overview) that previously ran from the web browser now run server-side rather than from the browser.

This means that some false positives may be triggered in existing installations after upgrading. This does not mean the checks are invalid or broken. It does mean that local configuration matters that may not have had obvious side effects previously may now prevent the tests from getting accurate results.

In nearly all cases the resolution is one or more of the following:

  • verifying all entries in trusted_domains and the value of overwrite.cli.url are valid, resolvable in DNS, and reachable from the Nextcloud Server itself
  • verifying that the Server can reach its own URL(s)
  • verifying all overwrite* config values are reasonable

In diagnosing the above, many admins have found it useful to review not only their config.php (for cleanup) but also:

  • their local DNS resolvers and /etc/hosts files for reasonableness
  • their firewall configurations
  • their container network configuration if using Docker/etc (especially for outbound connectivity)

Tip

Testing of connectivity and reachability of specific URLs can usually be tested from servers or containers via curl or wget.

Critical change

Monitoring

Beginning with Nextcloud 28, the monitoring endpoint no longer provides information about available app updates, as gathering the data always involves at least one external request to apps.nextcloud.com.

You can still ask the monitoring endpoint to show new app updates by using the URL parameter skipApps=false. However, please do not check this endpoint too often.

https://github.com/nextcloud/serverinfo#api

Critical change

Previews for Office files using LibreOffice

Nextcloud can generate previews for Office files using LibreOffice.

Since Nextcloud 28, you can also create previews for EMF files. To enable it, add 'OC\Preview\EMF' to enabledPreviewProviders.

Until Nextcloud 28, the same LibreOffice user profile was used to generate the previews. LibreOffice can only be invoked once per user profile, so the generation of a preview for an office file would fail if another one were created right now.

Beginning with Nextcloud 28, a different LibreOffice user profile is used for each file. Downside: If you upload 100 emf files, you may end up with 100 LibreOffice invocations. Though, you can use preview_concurrency_new and preview_concurrency_all to limit the number of previews that can be generated concurrently when php-sysvsem is available.

The configuration option preview_office_cl_parameters was removed with Nextcloud 28. We expect LibreOffice to be started with the given parameters, so it's unfavorable to have a configuration option to change the parameters. Please reach out to us via https://github.com/nextcloud/server/pull/41395 if that's causing any trouble for you.

Tip

Previews for EMF files can be enabled without a local LibreOffice installation if you are already using Nextcloud Office / Collabora. Make sure you have Nextcloud Office 8.3.0 installed and add 'OCA\Richdocuments\Preview\EMF' to enabledPreviewProviders.

Full release notes for 28.0.0

28.0.1 – 28.0.4: no action items (4 versions)

28.0.5 – 28.0.13: released after 29.0.0; not on this route

28.0.14 2024-12-12

Full release notes for 28.0.14

29.0.0 – 29.0.7: no action items (8 versions)

29.0.8 – 29.0.15: released after 30.0.0; not on this route

29.0.16 2025-04-17

Full release notes for 29.0.16

30.0.0 2024-09-25

Quoted from docs.nextcloud.com/server/latest/admin_manual/release_notes/upgrade_to_30.html

Critical change

System requirements

  • PHP 8.1 is now deprecated but still supported.
  • PHP 8.0 is no longer supported.
  • PostgreSQL 9.4 is no longer supported.
  • MariaDB 10.3 and 10.5 are no longer supported.

Critical change

Web server configuration

Make sure that your web server is serving files with the webp extension (WebP images) correctly as static assets. This is included in the shipped .htaccess file but if you use another web server or custom configuration you need to check this manually.

Critical change

Nextcloud configuration

Changes to the available options in config.php.

  • The option blacklisted_files is now deprecated and replaced with forbidden_filenames
  • The option forbidden_chars is now deprecated and replaced with forbidden_filename_characters
  • The option forbidden_filename_basenames was added to allow bocking files with specific basenames (the filename without extension (before the first dot))
  • The option forbidden_filename_extensions was added to allow blocking extensions from being used on filenames

Critical change

Previews for PDF files with Imaginary

The preview provider OC\Preview\Imaginary is no longer generating previews for PDF files. Add the new preview provider OC\Preview\ImaginaryPDF to enabledPreviewProviders to enable preview generation with Imaginary for PDF files.

Critical change

Automated clean-up of app password

Nextcloud 30 will clean-up unused app passwords.

Critical change

Monitoring: Counting of active users

Starting with Nextcloud 30.0.12 the monitoring app was adjusted to count the active users in the same way as occ user:report and the support app.

Critical change

AppAPI (app_api) is now a default app

Starting with Nextcloud 30.0.1, the AppAPI app is included and enabled by default. See ExApps management for details.

You can disable this app in the standard manner via the Apps menu if you do not expect to use AppAPI integrations in the near future.

If AppAPI is disabled, other apps that depend on it will not be visible in the app store. AppAPI-related setup checks will also be deactivated.

Full release notes for 30.0.0

30.0.1 – 30.0.6: no action items (6 versions)

30.0.7 – 30.0.16: released after 31.0.0; not on this route

30.0.17 2025-10-23

Full release notes for 30.0.17

31.0.0 2025-02-25

Quoted from docs.nextcloud.com/server/latest/admin_manual/release_notes/upgrade_to_31.html

Critical change

System requirements

  • PHP 8.1 is now deprecated but still supported.
  • PHP 8.4 is now supported, but 8.3 is recommended.

Critical change

Database configuration

Other row formats than DYNAMIC for MySQL and MariaDB databases will issue a warning since Nextcloud 24, as they often cause performance issues. With Nextcloud 31 a more prominent new setup warning for this was added.

The row format can be changed via ALTER TABLE DDL commands during a maintenance window. Changing the row format from COMPRESSED to DYNAMIC requires about 2x the disk space and may take a long time depending on the size of the database. See the MySQL documentation for more information. If you're not sure how to do this, you can find some tips and tricks from the community.

Critical change

PHP configuration

We have a new setup warning to check if the memory reserved for APCu is high enough. If you see this warning, you should increase the memory reserved for APCu. You can do this by increasing the value of the apc.shm_size directive in your php.ini file. It is generally advised to review this value and increase it if necessary depending on your instance size.

Critical change

Nextcloud configuration

Maximum chunk size

We have adjusted the default maximum chunk size for big file uploading. Previously it was set to 10MiB, it is now increased to 100MiB.

Also the configuration was moved from an app configuration to the system configuration (config.php). If you set up a custom value previously the value will be automatically migrated to the system configuration during the update. But if you need to set a new custom value you need now to use the system configuration, see also Adjust chunk size on Nextcloud side.

Critical change

Monitoring: Counting of active users

Starting with Nextcloud 31.0.6 the monitoring app was adjusted to count the active users in the same way as occ user:report and the support app.

Critical change

Previews

Starting with Nextcloud 31.0.10, the preview provider for MP3 files, which reads cover images embedded in the files, is disabled by default for performance and stability reasons. See Previews configuration for details on how to enable or disable the preview provider.

Critical change

Same text as in 30.0.0, above.

Full release notes for 31.0.0

31.0.1 – 31.0.9: no action items (9 versions)

31.0.10 – 31.0.13: released after 32.0.0; not on this route

31.0.14 2026-02-12

Full release notes for 31.0.14

32.0.0 2025-09-27

Quoted from docs.nextcloud.com/server/latest/admin_manual/release_notes/upgrade_to_32.html

Critical change

Same text as in 31.0.0, above.

Critical change

Web server configuration

  • Setup checks do not check for the X-XSS-Protection response header anymore. It has been removed from Nextcloud's .htaccess and you may want to adjust your webserver config to not serve it anymore. XSS filtering was supported only until Chromium 78 and similarly old browsers, but had been found to cause more issues, including attack vectors, than it solved. Nowadays, aside of not serving the header at all, the only generally recommended value is 0. More context can be found in the OWASP Cheat Sheet Series.

Critical change

Monitoring: Counting of active users

The monitoring app was adjusted to count the active users in the same way as occ user:report and the support app.

Critical change

System address book

During the upgrade to Nextcloud 32 the system address book might become disabled if the amount of system users exceeds the default limit of 5000 users. This is to prevent performance issues. You can re-enable the system address book using the command line or administration interface.

For more information about the system address book, see the documentation. System Address Book

Critical change

Previews

Starting with Nextcloud 32.0.1, the preview provider for MP3 files, which reads cover images embedded in the files, is disabled by default for performance and stability reasons. See Previews configuration for details on how to enable or disable the preview provider.

Critical change

AppAPI (app_api) setup checks expanded

Starting with Nextcloud 30.0.1, the AppAPI app is included and enabled by default. See ExApps management for details. Additionally, as of version 32.0.0, the AppAPI has expanded its setup checks.

You can disable this app in the standard manner via the Apps menu if you do not expect to use AppAPI integrations in the near future.

If AppAPI is disabled, other apps that depend on it will not be visible in the app store. AppAPI-related setup checks will also be deactivated.

Critical change

S3 integrity protections enabled, configuration update may be needed

The AWS SDK for PHP was updated and now supports the data integrity protections for S3.

>= Nextcloud 32.0.2: If your S3 backend does not support the data integrity protection, you can disable it by adding 'request_checksum_calculation' => 'when_required', and 'response_checksum_validation' => 'when_required', to the object store configuration.

>= Nextcloud 32.0.3: S3 data integrity protections are disabled by default and are now opt-in.

If your S3 backend does not support this, you may see an error such as Checksum Type mismatch occurred, expected checksum Type: null, actual checksum Type: crc32 in your logs when uploading files.

More details about data integrity protections for S3 can be found at https://docs.aws.amazon.com/sdkref/latest/guide/feature-dataintegrity.html and https://github.com/aws/aws-sdk-php/discussions/3100.

Full release notes for 32.0.0

32.0.1 – 32.0.6: no action items (6 versions)

32.0.7 – 32.0.14: released after 33.0.0; not on this route

32.0.15 2026-09-10

Full release notes for 32.0.15

33.0.0 2026-02-18

Quoted from docs.nextcloud.com/server/latest/admin_manual/release_notes/upgrade_to_33.html

Critical change

System requirements

  • PHP 8.5 is now supported.
  • PHP 8.2 is now deprecated but still supported.
  • PHP 8.1 is no longer supported.
  • Oracle 11g is no longer supported.
  • PostgreSQL 13 is no longer supported.

If you configured restrictions on which domains can be contacted on the internet, you need to add connectivity.nextcloud.com to the allowlist, as it’s now used by default to test internet connectivity instead of www.nextcloud.com. You can also configure any other URL to use in the configuration instead. See Connections to remote servers.

Critical change

Previews

The preview provider for MP3 files, which reads cover images embedded in the files, is disabled by default for performance and stability reasons. See Previews configuration for details on how to enable or disable the preview provider.

Critical change

Snowflake IDs

This version of Nextcloud ships with Snowflake IDs. Those IDs include the creation time of object, a sequence ID and a server ID. The server ID should now be configured in your config.php file or using environment variables. See Configuration Parameters for more information.

Critical change

OpenMetrics endpoint

Nextcloud 33 introduces a /metrics endpoint that can be integrated into every OpenMetrics (Prometheus) system. For security, it only answers on localhost by default.

See Monitoring for more information about it.

Critical change

Default user agent for outgoing requests changed

Starting with this release, the default user agent for requests done by the instance was changed from Nextcloud Server Crawler to Nextcloud-Server-Crawler/X.Y.Z, where X.Y.Z is the current server version.

Critical change

TaskProcessing worker command

Previously we instructed admins to run occ background-job:worker <JobClass> to speed up AI task processing. This recommendation has changed to running occ taskprocessing:worker, which handles parallel execution better. Make sure to update your setup.

See Overview for more information about this.

Full release notes for 33.0.0

33.0.1 – 33.0.5: no action items (5 versions)

33.0.6 – 33.0.8: released after 34.0.0; not on this route

33.0.9 2026-09-10

Full release notes for 33.0.9

34.0.0 – 34.0.3: no action items (4 versions)

34.0.4 2026-09-10

Full release notes for 34.0.4

35.0.0 2026-09-15

Critical change

System requirements

  • PHP 8.2 is no longer supported.
  • The list of officially supported operating system has been updated:
  • The minimum supported version of SUSE Linux Enterprise Server 15 has been bumped to SP7.
  • The minimum supported version of Debian Linux has been bumped to 13 (Trixie).
  • The minimum supported version of Ubuntu Linux has been bumped to 24.04.
  • The list of officially supported databases has been updated:
  • MariaDB 10.6 is out of support and thus Nextcloud dropped support for it. The minimum supported version of MariaDB is now 10.11 LTS.
  • MariaDB 12.3 is released as a new LTS version and is now supported by Nextcloud.
  • MySQL 8.0 is out of support and thus Nextcloud dropped support for it. The minimum supported version of MySQL is now 8.4 LTS.
  • MySQL 9.7 is released as a new LTS version and is now supported by Nextcloud.

Note

MySQL 9+ dropped support for MD5, some parts of the Nextcloud ecosystem might stilly rely on it. You need to make sure that after upgrading to MySQL 9+ you load the MySQL component for MD5 support, to do so run this on your MySQL 9+ server:

INSTALL COMPONENT 'file://component_classic_hashing';

From docs.nextcloud.com/server/latest/admin_manual/release_notes/upgrade_to_35.html

Full release notes for 35.0.0

35.0.1: no action items (1 version)

Release notes from github.com/nextcloud/server/releases, and Upgrade to Nextcloud 26, and Upgrade to Nextcloud 27, and Upgrade to Nextcloud 28, and Upgrade to Nextcloud 30, and Upgrade to Nextcloud 31, and Upgrade to Nextcloud 32, and Upgrade to Nextcloud 33, and Upgrade to Nextcloud 35, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. Nextcloud's GitHub release notes are lists of merged pull requests and mark nothing as breaking. What is quoted instead is the admin manual's “Critical changes” page for each major version (Upgrade to Nextcloud 26, 27, 28, 30, 31, 32, 33 and 35; there is none for 29 or 34), one item per section, labelled “Critical change”, on the x.0.0 release. The manual has no such pages before 26. Versions are covered from 23.0.0; GitHub has no complete release list before that. Required stops are the latest point release of each major version on the way, per the manual's upgrade page.