The problem is that many proxies will log passwords sent this way.
Placing the username and password in the URL results in the same TLS-protected HTTP header as normal basic authentication:
$ curl -v https://user:pass@example.com/page
[...]
> GET /page HTTP/2
> Host: example.com
> authorization: Basic dXNlcjpwYXNz
> user-agent: curl/7.77.0
> accept: */*
>
Even over HTTP, a proxy that intentionally logs the URL accessed would not see the username and password in the initial "GET" line. It would have to go out of its way to extract it from the Authorization header, which is still present regardless of how the basic authentication was initiated.If you meant user agents logging the username and password as part of the history, I suppose you could consider that a bug but it could also be considered a feature. Presumably if you're using a URL of that form your intent is in fact to be able to link or bookmark the URL including the credentials.
And corporate proxies man in the middle everyone, because the entity that controls the proxy also controls the certificate on the computer.