Nextcloud Server 24.0.0 → 35.0.1
82 versions, 40 critical-change sections in 8 versions (2 repeat an earlier entry), 11 required stops
Required stops
- 24.0.12
Latest 24.x release.
Nextcloud must be upgraded step by step:
- Before you can upgrade to the next major release, you need to upgrade to the latest point release of your current major version.
- Then run the upgrade again to upgrade to the next major release’s latest point release.
- You cannot skip major releases. Please re-run the upgrade until you have reached the highest available (or applicable) release.
- Example: 18.0.5 -> 18.0.11 -> 19.0.5 -> 20.0.2
Wait for background migrations to finish after major upgrades. After upgrading to a new major version, some migrations are scheduled to run as a background job. If you plan to upgrade directly to another major version (e.g. 24 -> 25 -> 26) you need to make sure these migrations were executed before starting the next upgrade. To do so you should run the
cron.phpfile 2-3 times, for example:$ sudo -E -u www-data php -f /var/www/nextcloud/cron.phpSource: https://docs.nextcloud.com/server/latest/admin_manual/maintenance/upgrade.html (checked 2026-09-26)
- 25.0.13 Latest 25.x release. Same rule as 24.0.12.
- 26.0.13 Latest 26.x release. Same rule as 24.0.12.
- 27.1.11 Latest 27.x release. Same rule as 24.0.12.
- 28.0.14 Latest 28.x release. Same rule as 24.0.12.
- 29.0.16 Latest 29.x release. Same rule as 24.0.12.
- 30.0.17 Latest 30.x release. Same rule as 24.0.12.
- 31.0.14 Latest 31.x release. Same rule as 24.0.12.
- 32.0.15 Latest 32.x release. Same rule as 24.0.12.
- 33.0.9 Latest 33.x release. Same rule as 24.0.12.
- 34.0.4 Latest 34.x release. Same rule as 24.0.12.
Version by version, oldest first
24.0.1 – 24.0.6: no action items (6 versions)
24.0.7 – 24.0.11: released after 25.0.0; not on this route
24.0.12 2023-04-20
Required stop
25.0.0 – 25.0.4: no action items (5 versions)
25.0.5 – 25.0.12: released after 26.0.0; not on this route
25.0.13 2023-10-28
Required stop
26.0.0 2023-03-21
Quoted from docs.nextcloud.com/server/latest/admin_manual/release_notes/upgrade_to_26.html
Critical change
System requirements
- PHP 8.2 is now supported, but 8.1 is recommended.
- PHP 7.4 is no longer supported.
Critical change
System email
The software component to send system emails (notifications, invites, password reset, etc) had to be replaced. The new library should work without any changes out of the box for most setups.
A brief overview of changes:
- STARTTLS cannot be enforced. It will be used automatically if the mail server supports it. The encryption type should be set to 'None/STARTTLS' in this case.
- Self signed certificates now need to be explicitly enabled, see this guide for an example on how to configure this.
- NTLM authentication for Microsoft Exchange is not supported by the new mailer library. Try using basic authentication instead.
See for more information: Mail Providers.
Critical change
DAV sync tokens retention
A mechanism to clean up old CalDAV and CardDAV sync tokens has been added. See CalDAV retention and CardDAV retention and make sure it fits your installation size.
Critical change
Web server configuration
- The recommended nginx configuration changed.
26.0.1 – 26.0.2: no action items (2 versions)
26.0.3 – 26.0.12: released after 27.0.0; not on this route
26.0.13 2024-03-28
Required stop
27.0.0 2023-06-13
Quoted from docs.nextcloud.com/server/latest/admin_manual/release_notes/upgrade_to_27.html
Critical change
System requirements
- PHP 8.2 is recommended over PHP 8.1.
- PHP 8.0 is deprecated and might be removed in Nextcloud 28.
Critical change
Exposed system address book
Nextcloud 27 exposes the system address book. Restrict the enumeration settings if your users should not see other users.
Critical change
Web server configuration
- The recommended nginx configuration changed as Nextcloud now supports module javascript with the
.mjsand audio files with.ogg/.flacextension, make sure to add these extensions to the list of static files.
27.0.1 – 27.1.4: no action items (7 versions)
27.1.5 – 27.1.9: released after 28.0.0; not on this route
27.1.11 2024-06-25
Required stop
28.0.0 2023-12-12
Quoted from docs.nextcloud.com/server/latest/admin_manual/release_notes/upgrade_to_28.html
Critical change
System requirements
- PHP 8.3 is now supported, but 8.2 is recommended.
Critical change
Web server configuration
- The recommended nginx configuration changed as Nextcloud Talk now serves audio files with
.ogg/.flacextension, make sure to add these extensions to the list of static files. - As some core app now make use of JavaScript modules, make sure your web server is not rewriting requests to
.mjsfiles, but serves them withtext/javascriptMIME type and properCache-Controlheader, like.jsand other static file extensions.
- When using Apache with
.htaccessconfiguration, this will be done automatically. - For Nginx, please refer to our recommended Nginx configuration.
- For other setups, make sure to add
.mjsto the list of static file extensions in web server configs and in case define its MIME type in/etc/mime.types.
Critical change
Setup Checks
The setup checks (the ones visible under Administration settings->Overview) that previously ran from the web browser now run server-side rather than from the browser.
This means that some false positives may be triggered in existing installations after upgrading. This does not mean the checks are invalid or broken. It does mean that local configuration matters that may not have had obvious side effects previously may now prevent the tests from getting accurate results.
In nearly all cases the resolution is one or more of the following:
- verifying all entries in
trusted_domainsand the value ofoverwrite.cli.urlare valid, resolvable in DNS, and reachable from the Nextcloud Server itself - verifying that the Server can reach its own URL(s)
- verifying all
overwrite*config values are reasonable
In diagnosing the above, many admins have found it useful to review not only their config.php (for cleanup) but also:
- their local DNS resolvers and
/etc/hostsfiles for reasonableness - their firewall configurations
- their container network configuration if using Docker/etc (especially for outbound connectivity)
Tip
Testing of connectivity and reachability of specific URLs can usually be tested from servers or containers via
curlorwget.
Critical change
Monitoring
Beginning with Nextcloud 28, the monitoring endpoint no longer provides information about available app updates, as gathering the data always involves at least one external request to apps.nextcloud.com.
You can still ask the monitoring endpoint to show new app updates by using the URL parameter skipApps=false. However, please do not check this endpoint too often.
Critical change
Previews for Office files using LibreOffice
Nextcloud can generate previews for Office files using LibreOffice.
Since Nextcloud 28, you can also create previews for EMF files. To enable it, add 'OC\Preview\EMF' to enabledPreviewProviders.
Until Nextcloud 28, the same LibreOffice user profile was used to generate the previews. LibreOffice can only be invoked once per user profile, so the generation of a preview for an office file would fail if another one were created right now.
Beginning with Nextcloud 28, a different LibreOffice user profile is used for each file. Downside: If you upload 100 emf files, you may end up with 100 LibreOffice invocations. Though, you can use preview_concurrency_new and preview_concurrency_all to limit the number of previews that can be generated concurrently when php-sysvsem is available.
The configuration option preview_office_cl_parameters was removed with Nextcloud 28. We expect LibreOffice to be started with the given parameters, so it's unfavorable to have a configuration option to change the parameters. Please reach out to us via https://github.com/nextcloud/server/pull/41395 if that's causing any trouble for you.
Tip
Previews for EMF files can be enabled without a local LibreOffice installation if you are already using Nextcloud Office / Collabora. Make sure you have Nextcloud Office 8.3.0 installed and add
'OCA\Richdocuments\Preview\EMF'toenabledPreviewProviders.
28.0.1 – 28.0.4: no action items (4 versions)
28.0.5 – 28.0.13: released after 29.0.0; not on this route
28.0.14 2024-12-12
Required stop
29.0.0 – 29.0.7: no action items (8 versions)
29.0.8 – 29.0.15: released after 30.0.0; not on this route
29.0.16 2025-04-17
Required stop
30.0.0 2024-09-25
Quoted from docs.nextcloud.com/server/latest/admin_manual/release_notes/upgrade_to_30.html
Critical change
System requirements
- PHP 8.1 is now deprecated but still supported.
- PHP 8.0 is no longer supported.
- PostgreSQL 9.4 is no longer supported.
- MariaDB 10.3 and 10.5 are no longer supported.
Critical change
Web server configuration
Make sure that your web server is serving files with the webp extension (WebP images) correctly as static assets. This is included in the shipped .htaccess file but if you use another web server or custom configuration you need to check this manually.
Critical change
Nextcloud configuration
Changes to the available options in config.php.
- The option
blacklisted_filesis now deprecated and replaced withforbidden_filenames - The option
forbidden_charsis now deprecated and replaced withforbidden_filename_characters - The option
forbidden_filename_basenameswas added to allow bocking files with specific basenames (the filename without extension (before the first dot)) - The option
forbidden_filename_extensionswas added to allow blocking extensions from being used on filenames
Critical change
Previews for PDF files with Imaginary
The preview provider OC\Preview\Imaginary is no longer generating previews for PDF files. Add the new preview provider OC\Preview\ImaginaryPDF to enabledPreviewProviders to enable preview generation with Imaginary for PDF files.
Critical change
Automated clean-up of app password
Nextcloud 30 will clean-up unused app passwords.
Critical change
Monitoring: Counting of active users
Starting with Nextcloud 30.0.12 the monitoring app was adjusted to count the active users in the same way as occ user:report and the support app.
Critical change
AppAPI (app_api) is now a default app
Starting with Nextcloud 30.0.1, the AppAPI app is included and enabled by default. See ExApps management for details.
You can disable this app in the standard manner via the Apps menu if you do not expect to use AppAPI integrations in the near future.
If AppAPI is disabled, other apps that depend on it will not be visible in the app store. AppAPI-related setup checks will also be deactivated.
30.0.1 – 30.0.6: no action items (6 versions)
30.0.7 – 30.0.16: released after 31.0.0; not on this route
30.0.17 2025-10-23
Required stop
31.0.0 2025-02-25
Quoted from docs.nextcloud.com/server/latest/admin_manual/release_notes/upgrade_to_31.html
Critical change
System requirements
- PHP 8.1 is now deprecated but still supported.
- PHP 8.4 is now supported, but 8.3 is recommended.
Critical change
Database configuration
Other row formats than DYNAMIC for MySQL and MariaDB databases will issue a warning since Nextcloud 24, as they often cause performance issues. With Nextcloud 31 a more prominent new setup warning for this was added.
The row format can be changed via ALTER TABLE DDL commands during a maintenance window. Changing the row format from COMPRESSED to DYNAMIC requires about 2x the disk space and may take a long time depending on the size of the database. See the MySQL documentation for more information. If you're not sure how to do this, you can find some tips and tricks from the community.
Critical change
PHP configuration
We have a new setup warning to check if the memory reserved for APCu is high enough. If you see this warning, you should increase the memory reserved for APCu. You can do this by increasing the value of the apc.shm_size directive in your php.ini file. It is generally advised to review this value and increase it if necessary depending on your instance size.
Critical change
Nextcloud configuration
Maximum chunk size
We have adjusted the default maximum chunk size for big file uploading. Previously it was set to 10MiB, it is now increased to 100MiB.
Also the configuration was moved from an app configuration to the system configuration (config.php). If you set up a custom value previously the value will be automatically migrated to the system configuration during the update. But if you need to set a new custom value you need now to use the system configuration, see also Adjust chunk size on Nextcloud side.
Critical change
Monitoring: Counting of active users
Starting with Nextcloud 31.0.6 the monitoring app was adjusted to count the active users in the same way as occ user:report and the support app.
Critical change
Previews
Starting with Nextcloud 31.0.10, the preview provider for MP3 files, which reads cover images embedded in the files, is disabled by default for performance and stability reasons. See Previews configuration for details on how to enable or disable the preview provider.
Critical change
Same text as in 30.0.0, above.
31.0.1 – 31.0.9: no action items (9 versions)
31.0.10 – 31.0.13: released after 32.0.0; not on this route
31.0.14 2026-02-12
Required stop
32.0.0 2025-09-27
Quoted from docs.nextcloud.com/server/latest/admin_manual/release_notes/upgrade_to_32.html
Critical change
Same text as in 31.0.0, above.
Critical change
Web server configuration
- Setup checks do not check for the
X-XSS-Protectionresponse header anymore. It has been removed from Nextcloud's.htaccessand you may want to adjust your webserver config to not serve it anymore. XSS filtering was supported only until Chromium 78 and similarly old browsers, but had been found to cause more issues, including attack vectors, than it solved. Nowadays, aside of not serving the header at all, the only generally recommended value is0. More context can be found in the OWASP Cheat Sheet Series.
Critical change
Monitoring: Counting of active users
The monitoring app was adjusted to count the active users in the same way as occ user:report and the support app.
Critical change
System address book
During the upgrade to Nextcloud 32 the system address book might become disabled if the amount of system users exceeds the default limit of 5000 users. This is to prevent performance issues. You can re-enable the system address book using the command line or administration interface.
For more information about the system address book, see the documentation. System Address Book
Critical change
Previews
Starting with Nextcloud 32.0.1, the preview provider for MP3 files, which reads cover images embedded in the files, is disabled by default for performance and stability reasons. See Previews configuration for details on how to enable or disable the preview provider.
Critical change
AppAPI (app_api) setup checks expanded
Starting with Nextcloud 30.0.1, the AppAPI app is included and enabled by default. See ExApps management for details. Additionally, as of version 32.0.0, the AppAPI has expanded its setup checks.
You can disable this app in the standard manner via the Apps menu if you do not expect to use AppAPI integrations in the near future.
If AppAPI is disabled, other apps that depend on it will not be visible in the app store. AppAPI-related setup checks will also be deactivated.
Critical change
S3 integrity protections enabled, configuration update may be needed
The AWS SDK for PHP was updated and now supports the data integrity protections for S3.
>= Nextcloud 32.0.2: If your S3 backend does not support the data integrity protection, you can disable it by adding 'request_checksum_calculation' => 'when_required', and 'response_checksum_validation' => 'when_required', to the object store configuration.
>= Nextcloud 32.0.3: S3 data integrity protections are disabled by default and are now opt-in.
If your S3 backend does not support this, you may see an error such as Checksum Type mismatch occurred, expected checksum Type: null, actual checksum Type: crc32 in your logs when uploading files.
More details about data integrity protections for S3 can be found at https://docs.aws.amazon.com/sdkref/latest/guide/feature-dataintegrity.html and https://github.com/aws/aws-sdk-php/discussions/3100.
32.0.1 – 32.0.6: no action items (6 versions)
32.0.7 – 32.0.14: released after 33.0.0; not on this route
32.0.15 2026-09-10
Required stop
33.0.0 2026-02-18
Quoted from docs.nextcloud.com/server/latest/admin_manual/release_notes/upgrade_to_33.html
Critical change
System requirements
- PHP 8.5 is now supported.
- PHP 8.2 is now deprecated but still supported.
- PHP 8.1 is no longer supported.
- Oracle 11g is no longer supported.
- PostgreSQL 13 is no longer supported.
If you configured restrictions on which domains can be contacted on the internet, you need to add connectivity.nextcloud.com to the allowlist, as it’s now used by default to test internet connectivity instead of www.nextcloud.com. You can also configure any other URL to use in the configuration instead. See Connections to remote servers.
Critical change
Previews
The preview provider for MP3 files, which reads cover images embedded in the files, is disabled by default for performance and stability reasons. See Previews configuration for details on how to enable or disable the preview provider.
Critical change
Snowflake IDs
This version of Nextcloud ships with Snowflake IDs. Those IDs include the creation time of object, a sequence ID and a server ID. The server ID should now be configured in your config.php file or using environment variables. See Configuration Parameters for more information.
Critical change
OpenMetrics endpoint
Nextcloud 33 introduces a /metrics endpoint that can be integrated into every OpenMetrics (Prometheus) system. For security, it only answers on localhost by default.
See Monitoring for more information about it.
Critical change
Default user agent for outgoing requests changed
Starting with this release, the default user agent for requests done by the instance was changed from Nextcloud Server Crawler to Nextcloud-Server-Crawler/X.Y.Z, where X.Y.Z is the current server version.
Critical change
TaskProcessing worker command
Previously we instructed admins to run occ background-job:worker <JobClass> to speed up AI task processing. This recommendation has changed to running occ taskprocessing:worker, which handles parallel execution better. Make sure to update your setup.
See Overview for more information about this.
33.0.1 – 33.0.5: no action items (5 versions)
33.0.6 – 33.0.8: released after 34.0.0; not on this route
33.0.9 2026-09-10
Required stop
34.0.0 – 34.0.3: no action items (4 versions)
34.0.4 2026-09-10
Required stop
35.0.0 2026-09-15
Critical change
System requirements
- PHP 8.2 is no longer supported.
- The list of officially supported operating system has been updated:
- The minimum supported version of SUSE Linux Enterprise Server 15 has been bumped to SP7.
- The minimum supported version of Debian Linux has been bumped to 13 (Trixie).
- The minimum supported version of Ubuntu Linux has been bumped to 24.04.
- The list of officially supported databases has been updated:
- MariaDB 10.6 is out of support and thus Nextcloud dropped support for it. The minimum supported version of MariaDB is now 10.11 LTS.
- MariaDB 12.3 is released as a new LTS version and is now supported by Nextcloud.
- MySQL 8.0 is out of support and thus Nextcloud dropped support for it. The minimum supported version of MySQL is now 8.4 LTS.
- MySQL 9.7 is released as a new LTS version and is now supported by Nextcloud.
Note
MySQL 9+ dropped support for MD5, some parts of the Nextcloud ecosystem might stilly rely on it. You need to make sure that after upgrading to MySQL 9+ you load the MySQL component for MD5 support, to do so run this on your MySQL 9+ server:
INSTALL COMPONENT 'file://component_classic_hashing';
From docs.nextcloud.com/server/latest/admin_manual/release_notes/upgrade_to_35.html
35.0.1: no action items (1 version)
Release notes from github.com/nextcloud/server/releases, and Upgrade to Nextcloud 26, and Upgrade to Nextcloud 27, and Upgrade to Nextcloud 28, and Upgrade to Nextcloud 30, and Upgrade to Nextcloud 31, and Upgrade to Nextcloud 32, and Upgrade to Nextcloud 33, and Upgrade to Nextcloud 35, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. Nextcloud's GitHub release notes are lists of merged pull requests and mark nothing as breaking. What is quoted instead is the admin manual's “Critical changes” page for each major version (Upgrade to Nextcloud 26, 27, 28, 30, 31, 32, 33 and 35; there is none for 29 or 34), one item per section, labelled “Critical change”, on the x.0.0 release. The manual has no such pages before 26. Versions are covered from 23.0.0; GitHub has no complete release list before that. Required stops are the latest point release of each major version on the way, per the manual's upgrade page.