Upgrade Path

Nextcloud Server 31.0.0 → 35.0.1

32 versions, 14 critical-change sections in 3 versions, 4 required stops

Required stops

Version by version, oldest first

31.0.1 – 31.0.9: no action items (9 versions)

31.0.10 – 31.0.13: released after 32.0.0; not on this route

31.0.14 2026-02-12

Full release notes for 31.0.14

32.0.0 2025-09-27

Quoted from docs.nextcloud.com/server/latest/admin_manual/release_notes/upgrade_to_32.html

Critical change

System requirements

  • PHP 8.1 is now deprecated but still supported.
  • PHP 8.4 is now supported, but 8.3 is recommended.

Critical change

Web server configuration

  • Setup checks do not check for the X-XSS-Protection response header anymore. It has been removed from Nextcloud's .htaccess and you may want to adjust your webserver config to not serve it anymore. XSS filtering was supported only until Chromium 78 and similarly old browsers, but had been found to cause more issues, including attack vectors, than it solved. Nowadays, aside of not serving the header at all, the only generally recommended value is 0. More context can be found in the OWASP Cheat Sheet Series.

Critical change

Monitoring: Counting of active users

The monitoring app was adjusted to count the active users in the same way as occ user:report and the support app.

Critical change

System address book

During the upgrade to Nextcloud 32 the system address book might become disabled if the amount of system users exceeds the default limit of 5000 users. This is to prevent performance issues. You can re-enable the system address book using the command line or administration interface.

For more information about the system address book, see the documentation. System Address Book

Critical change

Previews

Starting with Nextcloud 32.0.1, the preview provider for MP3 files, which reads cover images embedded in the files, is disabled by default for performance and stability reasons. See Previews configuration for details on how to enable or disable the preview provider.

Critical change

AppAPI (app_api) setup checks expanded

Starting with Nextcloud 30.0.1, the AppAPI app is included and enabled by default. See ExApps management for details. Additionally, as of version 32.0.0, the AppAPI has expanded its setup checks.

You can disable this app in the standard manner via the Apps menu if you do not expect to use AppAPI integrations in the near future.

If AppAPI is disabled, other apps that depend on it will not be visible in the app store. AppAPI-related setup checks will also be deactivated.

Critical change

S3 integrity protections enabled, configuration update may be needed

The AWS SDK for PHP was updated and now supports the data integrity protections for S3.

>= Nextcloud 32.0.2: If your S3 backend does not support the data integrity protection, you can disable it by adding 'request_checksum_calculation' => 'when_required', and 'response_checksum_validation' => 'when_required', to the object store configuration.

>= Nextcloud 32.0.3: S3 data integrity protections are disabled by default and are now opt-in.

If your S3 backend does not support this, you may see an error such as Checksum Type mismatch occurred, expected checksum Type: null, actual checksum Type: crc32 in your logs when uploading files.

More details about data integrity protections for S3 can be found at https://docs.aws.amazon.com/sdkref/latest/guide/feature-dataintegrity.html and https://github.com/aws/aws-sdk-php/discussions/3100.

Full release notes for 32.0.0

32.0.1 – 32.0.6: no action items (6 versions)

32.0.7 – 32.0.14: released after 33.0.0; not on this route

32.0.15 2026-09-10

Full release notes for 32.0.15

33.0.0 2026-02-18

Quoted from docs.nextcloud.com/server/latest/admin_manual/release_notes/upgrade_to_33.html

Critical change

System requirements

  • PHP 8.5 is now supported.
  • PHP 8.2 is now deprecated but still supported.
  • PHP 8.1 is no longer supported.
  • Oracle 11g is no longer supported.
  • PostgreSQL 13 is no longer supported.

If you configured restrictions on which domains can be contacted on the internet, you need to add connectivity.nextcloud.com to the allowlist, as it’s now used by default to test internet connectivity instead of www.nextcloud.com. You can also configure any other URL to use in the configuration instead. See Connections to remote servers.

Critical change

Previews

The preview provider for MP3 files, which reads cover images embedded in the files, is disabled by default for performance and stability reasons. See Previews configuration for details on how to enable or disable the preview provider.

Critical change

Snowflake IDs

This version of Nextcloud ships with Snowflake IDs. Those IDs include the creation time of object, a sequence ID and a server ID. The server ID should now be configured in your config.php file or using environment variables. See Configuration Parameters for more information.

Critical change

OpenMetrics endpoint

Nextcloud 33 introduces a /metrics endpoint that can be integrated into every OpenMetrics (Prometheus) system. For security, it only answers on localhost by default.

See Monitoring for more information about it.

Critical change

Default user agent for outgoing requests changed

Starting with this release, the default user agent for requests done by the instance was changed from Nextcloud Server Crawler to Nextcloud-Server-Crawler/X.Y.Z, where X.Y.Z is the current server version.

Critical change

TaskProcessing worker command

Previously we instructed admins to run occ background-job:worker <JobClass> to speed up AI task processing. This recommendation has changed to running occ taskprocessing:worker, which handles parallel execution better. Make sure to update your setup.

See Overview for more information about this.

Full release notes for 33.0.0

33.0.1 – 33.0.5: no action items (5 versions)

33.0.6 – 33.0.8: released after 34.0.0; not on this route

33.0.9 2026-09-10

Full release notes for 33.0.9

34.0.0 – 34.0.3: no action items (4 versions)

34.0.4 2026-09-10

Full release notes for 34.0.4

35.0.0 2026-09-15

Critical change

System requirements

  • PHP 8.2 is no longer supported.
  • The list of officially supported operating system has been updated:
  • The minimum supported version of SUSE Linux Enterprise Server 15 has been bumped to SP7.
  • The minimum supported version of Debian Linux has been bumped to 13 (Trixie).
  • The minimum supported version of Ubuntu Linux has been bumped to 24.04.
  • The list of officially supported databases has been updated:
  • MariaDB 10.6 is out of support and thus Nextcloud dropped support for it. The minimum supported version of MariaDB is now 10.11 LTS.
  • MariaDB 12.3 is released as a new LTS version and is now supported by Nextcloud.
  • MySQL 8.0 is out of support and thus Nextcloud dropped support for it. The minimum supported version of MySQL is now 8.4 LTS.
  • MySQL 9.7 is released as a new LTS version and is now supported by Nextcloud.

Note

MySQL 9+ dropped support for MD5, some parts of the Nextcloud ecosystem might stilly rely on it. You need to make sure that after upgrading to MySQL 9+ you load the MySQL component for MD5 support, to do so run this on your MySQL 9+ server:

INSTALL COMPONENT 'file://component_classic_hashing';

From docs.nextcloud.com/server/latest/admin_manual/release_notes/upgrade_to_35.html

Full release notes for 35.0.0

35.0.1: no action items (1 version)

Release notes from github.com/nextcloud/server/releases, and Upgrade to Nextcloud 32, and Upgrade to Nextcloud 33, and Upgrade to Nextcloud 35, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. Nextcloud's GitHub release notes are lists of merged pull requests and mark nothing as breaking. What is quoted instead is the admin manual's “Critical changes” page for each major version (Upgrade to Nextcloud 26, 27, 28, 30, 31, 32, 33 and 35; there is none for 29 or 34), one item per section, labelled “Critical change”, on the x.0.0 release. The manual has no such pages before 26. Versions are covered from 23.0.0; GitHub has no complete release list before that. Required stops are the latest point release of each major version on the way, per the manual's upgrade page.