The first release candidates for our next maintenance updates are here: Nextcloud 35.0.2, 34.0.5, and 33.0.10! ![]()
Your testing helps us catch issues before the final releases, so donât hesitate to try them out!
If something doesnât behave as expected, please let us know on the appropriate GitHub repository! ![]()
The final releases are planned for next week, on October 15, 2026.
Downloads
- Nextcloud Server
35.0.2 RC2on GitHub - Nextcloud Server
34.0.5 RC1on GitHub - Nextcloud Server
33.0.10 RC1on GitHub
Changelog
Nextcloud 35.0.2rc2
server
files_pdfviewer
Nextcloud 35.0.2rc1
server
- Fix(sharing): Use link_defaultExpDays for default expiration in web UI (server#64322)
- Fix(files_sharing): name the parent folder in inherited unshare actions (server#64349)
- Fix(files_sharing): cap share presets to the permissions the resharer (server#64482)
- Fix(encryption): keep version and size in sync for files not in the cache (server#64485)
- Perf(setupchecks): Donât load all tasks to calculate stats (server#64609)
- Fix: forbid newline characters in filenames (server#64613)
- Fix: correct cast ttl to int in KeyValueCache (server#64615)
- Add API to generate system report section (server#64631)
- Fix(Sharing): Enforce source to be accessible by the owner (server#64644)
- Fix(auth): keep remember-me cookies pointing at a live session token (server#64649)
- Take mount name into account when searching by filename. (server#64664)
- Always make user in external share manager explicit (server#64669)
- Fix: never block simple renames in SharesPlugin (server#64681)
- Chore: drop DropFederatedInvitesTable (server#64689)
- Feat(upgrade): localize app names if available on upgrade page (server#64693)
- Fix(files): keep deleting live photo peers after a missing one (server#64699)
- Fix(files_sharing): render share suggestion avatar when provided (server#64704)
- Fix(setupcheck): Print verbose info to allow finding out memory issues (server#64751)
- Refactor(Sharing): Simplify sorting (server#64752)
- Bump Hub 26 Spring-> Hub 26 Summer (server#64758)
- Hide âShared by linkâ when sharing by link is disabled (server#64768)
- Chore: Reduce ownership list (server#64837)
- Feat: add additional metadata to node webhooks (server#64847)
- Chore(i18n): Change error message for invalid circle to team (server#64848)
- Chore(i18n): Update error message for dot files restriction (server#64849)
- Chore(i18n): Fix typo in sanitized message for Windows support (server#64850)
- Fix(EmojiHelper): exclude non-latin letters from EmojiHelper (server#64866)
- Feat: make comment events webhook compatible (server#64868)
- Fix(Sharing): Fix recipient IDs on 32-bits (server#64870)
- Fix(files_external): preserve boolean mount options (server#64879)
- Ci(psalm): Fail taint analysis action when it had errors (server#64882)
- Fix(SchemaChecker): donât block on unexpected-table finding (server#64891)
- Preparations for Unified Sharing Legacy Sync (server#64892)
- Fix(adminaudit): Allow named placeholders via CriticalActionPerformedEvent (server#64895)
- Fix(cache): Check if $entry[âfileidâ] exists (server#64902)
- Fix(user_ldap): show %uid instead of %%uid in the login filter hint (server#64913)
- Fix: Make all app versions stable (server#64915)
- Perf(files): Only match search results against caches of their storage (server#64916)
- Unified sharing remote recipients (server#64919)
- Feat(files-search): Add push down negation optimizer (server#64923)
- Fix(session): only regenerate session id after valid remember-me cookie (server#64924)
- Fix(l10n): stop double-escaping the instance name in settings text (server#64933)
- Fix: Forward not found error in sabre (server#64939)
- Fix: allow copy or move on ownerless mounts when no new shares are added (server#64947)
- Bump 3rdparty to update aws sdk (server#64949)
- Fix(encryption): use the closest cached parent for the access list (server#64960)
- Fix(dav): stop recording no-op address book changes (server#64967)
- Feat: Add code integrity background job (server#64974)
- Fix(setup): only resolve MySQL SSL attributes when an option is set (server#64981)
- Fix(kerberos): Allow again to specify empty url (server#64990)
- Fix(ocp): Adjust since version to actual delivered versions (server#65002)
- Fix(theming): Fix imagick segmentation fault when rendering an app icon (server#65011)
- Deprecate long, non-lazy app config and user config (server#65012)
- Fix(db-usage): fix DB index usage query (server#65014)
- Fix(SchemaChecker): silence reports from db:add-missing-indices (server#65017)
- Fix(files_trashbin): make trashbin:expire continue on errors (server#65020)
- Fix(webhook-listeners): revert admin check and document delegation behaviour (server#65108)
- Fix: only use `unencrypted_size` if set to a value (server#65115)
- Fix(TaskProcessing): return the actual message in 412 responses (server#65119)
- Build(deps): bump phpseclib/phpseclib from 3.0.55 to 3.0.57 (server#65121)
- Test: enable filecache partitioning for one mysql test (server#65128)
- Fix(occ): dispatch password reset events for user:resetpassword (server#65133)
- Perf: Optimize deleting the list of invalid shares (server#65137)
- Fix(settings): let a failed app token creation surface to the user (server#65141)
- Test(integration): Use correct share type for file requests (server#65143)
- Fix(files_sharing): make send_password_by_talk reactive (server#65163)
- Fix(files): check internal path when rescanning after failed fopen (server#65170)
- Refactor(dav): replace sabre collection (server#65178)
- Fix(contactsmenu): remove scrollbars with dyslexia font (server#65190)
- Fix(encryption): ensure app is loaded on login (server#65211)
- Fix(auth): check reset link expiry against interactive login timestamp (server#65245)
- Ci(actions): Fix pinned versions (server#65247)
- Fix(dav): skip metadata handlers for non-updatable nodes (server#65252)
- Fix: use correct node when formatting share token (server#65259)
- Fix(unified-search): apply and close the custom date range dialog (server#65266)
- Test(admin_audit): improve event listener test coverage (server#65275)
- Chore: Update CODEOWNERS for IDP team (server#65284)
- Fix: Rely on isAdmin method to check if user is admin (server#65287)
- Fix(dav): restrict calendar and address book sharing to the owner (server#65300)
3rdparty
activity
- Fix: Use strict comparaison (activity#2986)
- Feat: Build js after merge (activity#2998)
- Perf: Cache public share (activity#3004)
- Perf: Use startActivityTransaction in a few more places (activity#3016)
app_api
- Fix(k8s): apply daemon registry mappings (app_api#1076)
- Fix(daemon): stop prefilling the daemon key in the templates (app_api#1084)
bruteforcesettings
- Fix: Limit mask to 32 bits for IPv4 (bruteforcesettings#1280)
- Ci(actions): Remove no-op workflow (bruteforcesettings#1285)
- Chore: Adjust codeowners (bruteforcesettings#1299)
circles
- Fix: resolve share mount for remote circle members (circles#2836)
- Fix: Expose circle:report (circles#2935)
- Fix(teams): hide circles the user is not a member of (circles#2942)
- Fix: Team wording (circles#2949)
- Feat: Build js after merge (circles#2978)
- Feat(workflow): Add fixup block (circles#2989)
- Fix(teams): show email to tell apart members with the same name (circles#3005)
- Fix: Add a synchronous fallback when loopback doesnât work (circles#3007)
- Fix(share): Hide circle shares of files in the trashbin (circles#3014)
files_lock
notifications
- Fix(activities): Remove notifications from expired activities (notifications#3419)
- Fix(webpush): Correctly hide already read notifications from webpush (notifications#3451)
serverinfo
- Fix(database): skip the replica rule when no replication is configured (serverinfo#1159)
- Fix(database): gate the table open cache rule on uptime like its siblings (serverinfo#1168)
- Only report alerts and warnings as failing checks (serverinfo#1169)
- Feat: expose Nextcloud AIO version in info API (serverinfo#1189)
text
- Fix(Cron): tear down file system between attachment clean up runs (text#9232)
- Fix(links): open links on click and link bubble on hover (text#9233)
- Fix(ImageView): center blurhash placeholder like the loaded image (text#9241)
- Test(playwright): try to fix flakiness of conflict resolution tests (text#9245)
- Fix: search decoration (text#9248)
- Fix(details): use a single open flag (text#9249)
- Fix(callouts): fix long words overflowing the editor width (text#9256)
- Update tiptap to 3.31.3 (text#9281)
- Fix: comments follow-ups (text#9289)
- Fix(image): keep data: URI images on markdown round-trip (text#9290)
- Perf: get all markdown files in one SQL query (text#9291)
- Fix(comparison): make source line labels extractable (text#9292)
- Perf(session): fetch document only once in SessionMiddleware (text#9295)
- Fix(CodeBlock): make sure buttons donât overlay content (text#9305)
- Fix(TableOfContents): donât display toc container on mobile (text#9308)
- Test(vitest): move `vi.mock()` to top of file (text#9321)
- Feat(edit): collaborate in other apps(deck) (text#9325)
- Fix(autosave): only save after changes in the editor (text#9350)
twofactor_nextcloud_notification
Nextcloud 34.0.5rc1
server
- Feat(search): Subdue header search input placeholder (server#60833)
- Fix(dashboard): update scrollbar contrast on background (server#62630)
- Fix(encryption): bind personal private key password inputs (server#62672)
- Fix: allow Enter on public share Download link (server#62770)
- Fix: multiple file selection on tab navigation (server#63214)
- Fix: Combined Calendar and Contacts Import (server#63334)
- Fix: fail uploads when uri does not match session/share token (server#63960)
- Fix: donât rely on constraint for filecache_extended âupsertâ when in transaction (server#63985)
- Fix: Unknown cli option (server#63988)
- Fix: filter system tag object IDs by user visibility (server#63991)
- Fix(files_external): map display names for groups (server#64010)
- Fix(sharing): Hide Allow download and sync option for federated (server#64013)
- Fix(tags): broken tag deletion on user delete (server#64089)
- Fix(metadata): bind chunked file ids in dropMetadataForFiles (server#64092)
- Master] fix(security): Update code signing revocation list (server#64097)
- Fix: protect share accept endpoint with CSRF token (server#64107)
- Fix: remove wrongly used system address book flag (server#64131)
- Fix(files_sharing): normalize share target on parent folder rename (server#64143)
- Fix(files_sharing): donât abort share:list when orphaned shares exist (server#64146)
- Use strict comparaison (server#64190)
- Fix: update left padding of public shares (server#64212)
- Chore: update flake inputs (server#64215)
- Refactor: correct small typo in isUpgradeRequired log message (server#64297)
- Fix(ci): Pin 32-bit (server#64304)
- Fix(sharing): Use link_defaultExpDays for default expiration in web UI (server#64321)
- Fix: preserve link shares on ownership transfer (server#64330)
- Allow quota write streams with unknown free space (server#64342)
- Fix: remove nested items from favorites view on unfavorite (server#64345)
- Fix(encryption): cap and invalidate key-cache (server#64355)
- Fix(files): Show confirmation dialog on delete hotkey press (server#64359)
- Fix(files_external): show that an unrestricted storage applies to all (server#64361)
- Fix(files_sharing): donât crash CleanupShareTarget when mount info is missing (server#64368)
- Fix: improve form validation feedback for login, account creation, and sharing (server#64373)
- Fix: show custom permissions when share is removed from edit bundle (server#64376)
- Fix: logs can leak sensitive information.. (server#64385)
- Fix: skip copying skeleton if the user has 0 quota (server#64397)
- Fix: use correct mimetype for theming logo (server#64409)
- Fix(files_sharing): only offer folders in file-request which are shareable (server#64415)
- Fix: scope group share child permission updates to usergroup (server#64419)
- Fix: Send password to owner when password sending fails, regardless of enforcement (server#64424)
- Fix(previews): set Content-Type header for Imaginary requests (server#64430)
- Fix(config): Donât print sensitive config when setting them (server#64443)
- Master] fix(security): Update code signing revocation list (server#64464)
- Fix: keep share visible for share owner when iinitiator is deactivated (server#64476)
- Fix(files_sharing): cap share presets to the permissions the resharer (server#64481)
- Fix(encryption): keep version and size in sync for files not in the cache (server#64484)
- Fix(files): validate dropped filenames before upload (server#64503)
- Fix(dav): keep tags on hidden files when setting tag object ids (server#64560)
- Fix(systemtags): offer every tag in the tag selects (server#64585)
- Fix(encryption): keep the encrypted version the copy was written with (server#64605)
- Perf(setupchecks): Donât load all tasks to calculate stats (server#64610)
- Fix: correct cast ttl to int in KeyValueCache (server#64614)
- Fix(CalDAV): set significant change flag properly (server#64616)
- Fix(caldav): explicitly check from component types (server#64618)
- Add API to generate system report section (server#64632)
- Fix(auth): keep remember-me cookies pointing at a live session token (server#64650)
- Take mount name into account when searching by filename. (server#64665)
- Always make user in external share manager explicit (server#64670)
- Fix: never block simple renames in SharesPlugin (server#64676)
- Chore: drop DropFederatedInvitesTable (server#64688)
- Fix(files): keep deleting live photo peers after a missing one (server#64698)
- Master] fix(security): Update code signing revocation list (server#64721)
- Fix(dav): compare sync token retention against an absolute cutoff (server#64730)
- Hide âShared by linkâ when sharing by link is disabled (server#64767)
- Chore: Reduce ownership list (server#64836)
- Feat: add additional metadata to node webhooks (server#64846)
- Fix(files_external): preserve boolean mount options (server#64878)
- Ci(psalm): Fail taint analysis action when it had errors (server#64883)
- Fix(adminaudit): Allow named placeholders via CriticalActionPerformedEvent (server#64894)
- Fix(cache): Check if $entry[âfileidâ] exists (server#64903)
- Fix(user_ldap): show %uid instead of %%uid in the login filter hint (server#64914)
- Perf(files): Only match search results against caches of their storage (server#64917)
- Fix(session): only regenerate session id after valid remember-me cookie (server#64926)
- Bump 3rdparty to update aws sdk (server#64928)
- Fix: allow copy or move on ownerless mounts when no new shares are added (server#64930)
- Fix(l10n): stop double-escaping the instance name in settings text (server#64934)
- Fix(encryption): use the closest cached parent for the access list (server#64961)
- Fix(dav): stop recording no-op address book changes (server#64966)
- Feat: Add code integrity background job (server#64973)
- Fix(files_external): propagate child copy failures in AmazonS3::copy() (server#65003)
- Fix(theming): Fix imagick segmentation fault when rendering an app icon (server#65010)
- Fix(files_trashbin): make trashbin:expire continue on errors (server#65019)
- Fix(files_trashbin): misleading trashbin:expire output when expiration is disabled (server#65021)
- Fix(webhook-listeners): revert admin check and document delegation behaviour (server#65107)
- Fix: only use `unencrypted_size` if set to a value (server#65114)
- Fix(TaskProcessing): return the actual message in 412 responses (server#65118)
- Fix(occ): dispatch password reset events for user:resetpassword (server#65134)
- Test(integration): Use correct share type for file requests (server#65152)
- Fix(files_sharing): make send_password_by_talk reactive (server#65164)
- Fix(files): check internal path when rescanning after failed fopen (server#65169)
- Refactor(dav): replace sabre collection (server#65177)
- Fix(contactsmenu): remove scrollbars with dyslexia font (server#65189)
- Fix(auth): check reset link expiry against interactive login timestamp (server#65246)
- Ci(actions): Fix pinned versions (server#65249)
- Fix(dav): skip metadata handlers for non-updatable nodes (server#65251)
- Fix: use correct node when formatting share token (server#65260)
- Chore: Update CODEOWNERS for IDP team (server#65285)
- Fix: Rely on isAdmin method to check if user is admin (server#65288)
- Fix(dav): restrict calendar and address book sharing to the owner (server#65301)
3rdparty
activity
app_api
- Fix(k8s): check daemon reachability by deploy id (app_api#1027)
- Test(exapp_integration): add a browser test that the admin settings page renders (app_api#1035)
- Fix(k8s): apply daemon registry mappings (app_api#1075)
- Fix(daemon): stop prefilling the daemon key in the templates (app_api#1085)
bruteforcesettings
circles
- Fix(promote-owner): avoid DB errors on PostgreSQL and SQLite (circles#2916)
- Fix: Expose circle:report (circles#2934)
- Fix: Remove deadcode (circles#2952)
- Feat(workflow): Add fixup block (circles#2988)
- Fix: Add a synchronous fallback when loopback doesnât work (circles#3006)
- Fix(share): Hide circle shares of files in the trashbin (circles#3015)
files_lock
files_pdfviewer
logreader
photos
text
- Fix(print): hide files list when printing page (text#9205)
- Fix(SyncService): Behave like an idle disconnect on 403 responses (text#9209)
- Fix(Cron): tear down file system between attachment clean up runs (text#9231)
- Fix(links): open links on click and link bubble on hover (text#9234)
- Fix(ImageView): center blurhash placeholder like the loaded image (text#9240)
- Test(playwright): try to fix flakiness of conflict resolution tests (text#9246)
- Fix: search decoration (text#9247)
- Fix(callouts): fix long words overflowing the editor width (text#9255)
- Perf(session): fetch document only once in SessionMiddleware (text#9296)
- Fix(CodeBlock): make sure buttons donât overlay content (text#9306)
- Fix(TableOfContents): donât display toc container on mobile (text#9307)
- Fix(files): await FilesSettings before mounting (text#9344)
- Fix(autosave): only save after changes in the editor (text#9352)
twofactor_nextcloud_notification
- Ci(nextcloud-ocp): Remove old no-op approve-merge action (twofactor_nextcloud_notification#1531)
- Chore: Adjust codeowners (twofactor_nextcloud_notification#1546)
viewer
- Stable35] fix: optimize file lookup for large folders (viewer#3389)
- Fix(viewerAction): replace the history entry when closing the viewer (viewer#3392)
Nextcloud 33.0.10rc1
server
- Fix: track time spent in recursive markOrRun calls (server#61552)
- Fix(dashboard): update scrollbar contrast on background (server#62629)
- Fix(encryption): bind personal private key password inputs (server#62671)
- Fix: allow Enter on public share Download link (server#62769)
- Fix: multiple file selection on tab navigation (server#63213)
- Fix(cardDav): Only update user card on actual mapped propreties changes (server#63769)
- Fix: fail uploads when uri does not match session/share token (server#63961)
- Fix: donât rely on constraint for filecache_extended âupsertâ when in transaction (server#63984)
- Fix: filter system tag object IDs by user visibility (server#63992)
- Fix(files_external): map display names for groups (server#64009)
- Fix: Unknown cli option (server#64012)
- Fix(sharing): Hide Allow download and sync option for federated (server#64014)
- Fix(tags): broken tag deletion on user delete (server#64088)
- Master] fix(security): Update code signing revocation list (server#64098)
- Fix: protect share accept endpoint with CSRF token (server#64108)
- Fix: remove wrongly used system address book flag (server#64130)
- Fix(files_sharing): normalize share target on parent folder rename (server#64142)
- Fix(files_sharing): donât abort share:list when orphaned shares exist (server#64147)
- Fix: update left padding of public shares (server#64211)
- Chore: update flake inputs (server#64214)
- Fix(ci): Pin 32-bit (server#64305)
- Fix(sharing): Use link_defaultExpDays for default expiration in web UI (server#64320)
- Fix: preserve link shares on ownership transfer (server#64329)
- Fix: remove nested items from favorites view on unfavorite (server#64346)
- Fix(encryption): cap and invalidate key-cache (server#64354)
- Fix(files): Show confirmation dialog on delete hotkey press (server#64358)
- Fix(files_external): show that an unrestricted storage applies to all (server#64360)
- Fix(files_sharing): donât crash CleanupShareTarget when mount info is missing (server#64366)
- Fix: show custom permissions when share is removed from edit bundle (server#64377)
- Fix: logs can leak sensitive information.. (server#64384)
- Fix(files_sharing): only offer folders in file-request which are shareable (server#64414)
- Fix: scope group share child permission updates to usergroup (server#64418)
- Fix: Send password to owner when password sending fails, regardless of enforcement (server#64423)
- Test: migrate from Cypress to playwright (server#64437)
- Fix(config): Donât print sensitive config when setting them (server#64463)
- Master] fix(security): Update code signing revocation list (server#64465)
- Fix: keep share visible for share owner when iinitiator is deactivated (server#64475)
- Fix(files_sharing): cap share presets to the permissions the resharer (server#64480)
- Fix(encryption): keep version and size in sync for files not in the cache (server#64483)
- Fix(dav): keep tags on hidden files when setting tag object ids (server#64561)
- Fix(systemtags): offer every tag in the tag selects (server#64584)
- Fix(encryption): keep the encrypted version the copy was written with (server#64604)
- Fix(CalDAV): set significant change flag properly (server#64617)
- Fix(caldav): explicitly check from component types (server#64619)
- Add API to generate system report section (server#64633)
- Fix(auth): keep remember-me cookies pointing at a live session token (server#64651)
- Fix: Combined Calendar and Contacts Import (server#64677)
- Fix: never block simple renames in SharesPlugin (server#64680)
- Chore: drop DropFederatedInvitesTable (server#64687)
- Master] fix(security): Update code signing revocation list (server#64720)
- Fix(dav): compare sync token retention against an absolute cutoff (server#64731)
- Hide âShared by linkâ when sharing by link is disabled (server#64766)
- Chore: Reduce ownership list (server#64835)
- Feat: add additional metadata to node webhooks (server#64845)
- Fix(files_external): preserve boolean mount options (server#64877)
- Ci(psalm): Fail taint analysis action when it had errors (server#64884)
- Fix(adminaudit): Allow named placeholders via CriticalActionPerformedEvent (server#64893)
- Fix(cache): Check if $entry[âfileidâ] exists (server#64904)
- Perf(files): Only match search results against caches of their storage (server#64918)
- Fix(session): only regenerate session id after valid remember-me cookie (server#64927)
- Fix: allow copy or move on ownerless mounts when no new shares are added (server#64946)
- Bump 3rdparty to update aws sdk (server#64950)
- Fix(encryption): use the closest cached parent for the access list (server#64962)
- Fix: only use `unencrypted_size` if set to a value (server#64964)
- Fix(dav): stop recording no-op address book changes (server#64965)
- Fix(files_external): propagate child copy failures in AmazonS3::copy() (server#65004)
- Fix(webhook-listeners): revert admin check and document delegation behaviour (server#65106)
- Fix: Forward not found error in sabre (server#65116)
- Fix(TaskProcessing): return the actual message in 412 responses (server#65117)
- Fix(occ): dispatch password reset events for user:resetpassword (server#65135)
- Test(integration): Use correct share type for file requests (server#65151)
- Fix(files_sharing): make send_password_by_talk reactive (server#65165)
- Fix(files): check internal path when rescanning after failed fopen (server#65168)
- Refactor(dav): replace sabre collection (server#65176)
- Fix(contactsmenu): remove scrollbars with dyslexia font (server#65188)
- Fix(dav): skip metadata handlers for non-updatable nodes (server#65250)
- Ci(actions): Fix pinned versions (server#65256)
- Fix: use correct node when formatting share token (server#65261)
- Chore: Update CODEOWNERS for IDP team (server#65286)
- Fix: Rely on isAdmin method to check if user is admin (server#65289)
- Fix(dav): restrict calendar and address book sharing to the owner (server#65302)
3rdparty
activity
circles
- Fix(promote-owner): avoid DB errors on PostgreSQL and SQLite (circles#2915)
- Fix: Expose circle:report (circles#2933)
- Fix: Remove deadcode (circles#2953)
- Feat(workflow): Add fixup block (circles#2987)
- Fix: Add a synchronous fallback when loopback doesnât work (circles#3009)
- Fix(share): Hide circle shares of files in the trashbin (circles#3016)
files_pdfviewer
- Add a vitest harness for the front-end (files_pdfviewer#1566)
- Bump pdf.js version (files_pdfviewer#1571)
logreader
photos
text
- Fix/autosave timer (text#8989)
- Fix(print): hide files list when printing page (text#9208)
- Fix(Cron): tear down file system between attachment clean up runs (text#9219)
- Fix(callouts): fix long words overflowing the editor width (text#9254)
- Fix(files): await FilesSettings before mounting (text#9343)
- Fix(autosave): only save after changes in the editor (text#9353)
twofactor_nextcloud_notification
- Ci(nextcloud-ocp): Remove old no-op approve-merge action (twofactor_nextcloud_notification#1530)
- Chore: Adjust codeowners (twofactor_nextcloud_notification#1545)