Nextcloud Server 31.0.0 → 32.0.0
11 versions, 7 critical-change sections in 1 version, 1 required stop
Required stops
- 31.0.14
Latest 31.x release.
Nextcloud must be upgraded step by step:
- Before you can upgrade to the next major release, you need to upgrade to the latest point release of your current major version.
- Then run the upgrade again to upgrade to the next major release’s latest point release.
- You cannot skip major releases. Please re-run the upgrade until you have reached the highest available (or applicable) release.
- Example: 18.0.5 -> 18.0.11 -> 19.0.5 -> 20.0.2
Wait for background migrations to finish after major upgrades. After upgrading to a new major version, some migrations are scheduled to run as a background job. If you plan to upgrade directly to another major version (e.g. 24 -> 25 -> 26) you need to make sure these migrations were executed before starting the next upgrade. To do so you should run the
cron.phpfile 2-3 times, for example:$ sudo -E -u www-data php -f /var/www/nextcloud/cron.phpSource: https://docs.nextcloud.com/server/latest/admin_manual/maintenance/upgrade.html (checked 2026-09-26)
Version by version, oldest first
31.0.1 – 31.0.9: no action items (9 versions)
31.0.10 – 31.0.13: released after 32.0.0; not on this route
31.0.14 2026-02-12
Required stop
32.0.0 2025-09-27
Quoted from docs.nextcloud.com/server/latest/admin_manual/release_notes/upgrade_to_32.html
Critical change
System requirements
- PHP 8.1 is now deprecated but still supported.
- PHP 8.4 is now supported, but 8.3 is recommended.
Critical change
Web server configuration
- Setup checks do not check for the
X-XSS-Protectionresponse header anymore. It has been removed from Nextcloud's.htaccessand you may want to adjust your webserver config to not serve it anymore. XSS filtering was supported only until Chromium 78 and similarly old browsers, but had been found to cause more issues, including attack vectors, than it solved. Nowadays, aside of not serving the header at all, the only generally recommended value is0. More context can be found in the OWASP Cheat Sheet Series.
Critical change
Monitoring: Counting of active users
The monitoring app was adjusted to count the active users in the same way as occ user:report and the support app.
Critical change
System address book
During the upgrade to Nextcloud 32 the system address book might become disabled if the amount of system users exceeds the default limit of 5000 users. This is to prevent performance issues. You can re-enable the system address book using the command line or administration interface.
For more information about the system address book, see the documentation. System Address Book
Critical change
Previews
Starting with Nextcloud 32.0.1, the preview provider for MP3 files, which reads cover images embedded in the files, is disabled by default for performance and stability reasons. See Previews configuration for details on how to enable or disable the preview provider.
Critical change
AppAPI (app_api) setup checks expanded
Starting with Nextcloud 30.0.1, the AppAPI app is included and enabled by default. See ExApps management for details. Additionally, as of version 32.0.0, the AppAPI has expanded its setup checks.
You can disable this app in the standard manner via the Apps menu if you do not expect to use AppAPI integrations in the near future.
If AppAPI is disabled, other apps that depend on it will not be visible in the app store. AppAPI-related setup checks will also be deactivated.
Critical change
S3 integrity protections enabled, configuration update may be needed
The AWS SDK for PHP was updated and now supports the data integrity protections for S3.
>= Nextcloud 32.0.2: If your S3 backend does not support the data integrity protection, you can disable it by adding 'request_checksum_calculation' => 'when_required', and 'response_checksum_validation' => 'when_required', to the object store configuration.
>= Nextcloud 32.0.3: S3 data integrity protections are disabled by default and are now opt-in.
If your S3 backend does not support this, you may see an error such as Checksum Type mismatch occurred, expected checksum Type: null, actual checksum Type: crc32 in your logs when uploading files.
More details about data integrity protections for S3 can be found at https://docs.aws.amazon.com/sdkref/latest/guide/feature-dataintegrity.html and https://github.com/aws/aws-sdk-php/discussions/3100.
Release notes from github.com/nextcloud/server/releases, and Upgrade to Nextcloud 32, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. Nextcloud's GitHub release notes are lists of merged pull requests and mark nothing as breaking. What is quoted instead is the admin manual's “Critical changes” page for each major version (Upgrade to Nextcloud 26, 27, 28, 30, 31, 32, 33 and 35; there is none for 29 or 34), one item per section, labelled “Critical change”, on the x.0.0 release. The manual has no such pages before 26. Versions are covered from 23.0.0; GitHub has no complete release list before that. Required stops are the latest point release of each major version on the way, per the manual's upgrade page.