Upgrade Path

Nextcloud Server 31.0.0 → 32.0.0

11 versions, 7 critical-change sections in 1 version, 1 required stop

Required stops

Version by version, oldest first

31.0.1 – 31.0.9: no action items (9 versions)

31.0.10 – 31.0.13: released after 32.0.0; not on this route

31.0.14 2026-02-12

Full release notes for 31.0.14

32.0.0 2025-09-27

Quoted from docs.nextcloud.com/server/latest/admin_manual/release_notes/upgrade_to_32.html

Critical change

System requirements

  • PHP 8.1 is now deprecated but still supported.
  • PHP 8.4 is now supported, but 8.3 is recommended.

Critical change

Web server configuration

  • Setup checks do not check for the X-XSS-Protection response header anymore. It has been removed from Nextcloud's .htaccess and you may want to adjust your webserver config to not serve it anymore. XSS filtering was supported only until Chromium 78 and similarly old browsers, but had been found to cause more issues, including attack vectors, than it solved. Nowadays, aside of not serving the header at all, the only generally recommended value is 0. More context can be found in the OWASP Cheat Sheet Series.

Critical change

Monitoring: Counting of active users

The monitoring app was adjusted to count the active users in the same way as occ user:report and the support app.

Critical change

System address book

During the upgrade to Nextcloud 32 the system address book might become disabled if the amount of system users exceeds the default limit of 5000 users. This is to prevent performance issues. You can re-enable the system address book using the command line or administration interface.

For more information about the system address book, see the documentation. System Address Book

Critical change

Previews

Starting with Nextcloud 32.0.1, the preview provider for MP3 files, which reads cover images embedded in the files, is disabled by default for performance and stability reasons. See Previews configuration for details on how to enable or disable the preview provider.

Critical change

AppAPI (app_api) setup checks expanded

Starting with Nextcloud 30.0.1, the AppAPI app is included and enabled by default. See ExApps management for details. Additionally, as of version 32.0.0, the AppAPI has expanded its setup checks.

You can disable this app in the standard manner via the Apps menu if you do not expect to use AppAPI integrations in the near future.

If AppAPI is disabled, other apps that depend on it will not be visible in the app store. AppAPI-related setup checks will also be deactivated.

Critical change

S3 integrity protections enabled, configuration update may be needed

The AWS SDK for PHP was updated and now supports the data integrity protections for S3.

>= Nextcloud 32.0.2: If your S3 backend does not support the data integrity protection, you can disable it by adding 'request_checksum_calculation' => 'when_required', and 'response_checksum_validation' => 'when_required', to the object store configuration.

>= Nextcloud 32.0.3: S3 data integrity protections are disabled by default and are now opt-in.

If your S3 backend does not support this, you may see an error such as Checksum Type mismatch occurred, expected checksum Type: null, actual checksum Type: crc32 in your logs when uploading files.

More details about data integrity protections for S3 can be found at https://docs.aws.amazon.com/sdkref/latest/guide/feature-dataintegrity.html and https://github.com/aws/aws-sdk-php/discussions/3100.

Full release notes for 32.0.0

Release notes from github.com/nextcloud/server/releases, and Upgrade to Nextcloud 32, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. Nextcloud's GitHub release notes are lists of merged pull requests and mark nothing as breaking. What is quoted instead is the admin manual's “Critical changes” page for each major version (Upgrade to Nextcloud 26, 27, 28, 30, 31, 32, 33 and 35; there is none for 29 or 34), one item per section, labelled “Critical change”, on the x.0.0 release. The manual has no such pages before 26. Versions are covered from 23.0.0; GitHub has no complete release list before that. Required stops are the latest point release of each major version on the way, per the manual's upgrade page.