swagger-compat-spec-parser 1.0.55 relies on httpclient 4.5.2 which relies on commons-codec 1.9 which has an information disclosure vulnerability which is resolved in version 1.13.
httpclient 5.1 is the first version that updates to commons-codec 1.13